CVE-2026-94144 | drogonframework drogon up to 1.9.13 ORM orm_lib/src/Criteria.cc makeCriteria filter sql injection

SecurityVulns

A vulnerability classified as critical was found in drogonframework drogon up to 1.9.13. This affects the function makeCriteria in the library orm_lib/src/Criteria.cc of the component ORM. Executing a manipulation of the argument filter can lead to sql injection.

This vulnerability appears as CVE-2026-94144. The attack may be performed from remote. In addition, an exploit is available.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More