CVE-2026-94143

Summary

A vulnerability was detected in drogonframework drogon up to 1.9.13. Affected by this issue is the function Mapper::orderBy in the library Mapper.h of the component ORM Mapper. Performing a manipulation of the argument sort results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Software

VendorProductVersion RangeStatus
drogonframeworkdrogon1.9.0affected
drogonframeworkdrogon1.9.1affected
drogonframeworkdrogon1.9.2affected
drogonframeworkdrogon1.9.3affected
drogonframeworkdrogon1.9.4affected
drogonframeworkdrogon1.9.5affected
drogonframeworkdrogon1.9.6affected
drogonframeworkdrogon1.9.7affected
drogonframeworkdrogon1.9.8affected
drogonframeworkdrogon1.9.9affected
drogonframeworkdrogon1.9.10affected
drogonframeworkdrogon1.9.11affected
drogonframeworkdrogon1.9.12affected
drogonframeworkdrogon1.9.13affected

Weaknesses

  • CWE-89: SQL Injection
  • CWE-74: Injection

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: yes
    • Technical Impact: partial

References