CVE-2026-84993 | MikroORM up to 6.6.15/7.1.6 Shared SQL Layer direction sql injection

SecurityVulns

A vulnerability described as critical has been identified in MikroORM up to 6.6.15/7.1.6. Impacted is the function em.find/em.findOne/em.findAndCount/QueryBuilder.orderBy/QueryBuilderHelper.getQueryOrderFromObject of the component Shared SQL Layer. The manipulation of the argument direction results in sql injection.

This vulnerability is identified as CVE-2026-84993. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More