What is CVE-2026-72558?
This critical SQL injection vulnerability affects CiviCRM up to version 6.18.alpha1. An authenticated staff member can exploit the unsanitized user input in the contact search RLIKE clause to read the entire database. Immediate update to the latest patched version of CiviCRM is strongly advised.
Azərbaycanca: Bu kritik SQL injection zəifliyi CiviCRM-in 6.18.alpha1 versiyasına qədər təsir edir. Doğrulanmış əməkdaşlar ('staff') əlaqə axtarışında RLIKE bəndinə təmizlənməmiş dəyər daxil edərək bütün verilənlər bazasını oxuya bilər. Dərhal CiviCRM-i ən son təhlükəsizlik yaması ilə yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of CiviCRM are affected by CVE-2026-72558?
This critical SQL injection vulnerability affects CiviCRM up to version 6.18.alpha1.
What privileges does an attacker need to exploit CVE-2026-72558?
The attacker must be an authenticated staff member.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.