CVE-2026-84993 | MikroORM up to 6.6.15/7.1.6 Shared SQL Layer direction sql injection
A vulnerability described as critical has been identified in MikroORM up to 6.6.15/7.1.6. Impacted is the function em.find/em.findOne/em.findAndCount/QueryBuilder.orderBy/QueryBuilderHelper.getQueryOrderFromObject of the component Shared SQL Layer. The manipulation of the argument direction results in sql injection.
This vulnerability is identified as CVE-2026-84993. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More