
🔴 CakePHP'de CVSS 9.2 seviyesinde iki kritik SQL Injection açığı için @abraxas_null tarafından public PoC yayınlandı: • CVE-2026-77635 — PostgreSQL / jsonPath • CVE-2026-79752 — cast() / dataType Her iki açık da uygun uygulama koşullarında kimlik doğrulaması gerektirmeden SQL Injection'a yol açabiliyor. PoC: http://github.com/abraxas/CVE-2026-77635 http://github.com/abraxas/CVE-2026-79752
Post summary
The tweet publicly discloses a Proof of Concept for two critical SQL injection vulnerabilities in CakePHP (CVEs 2026-77635 and 2026-79752) with CVSS 9.2 details, but provides no evidence of active exploitation, named exploit tools, or available patches.



