CVE-2026-77635 | CakePHP up to 5.1.9/5.2.14/5.3.6 jsonValue jsonPath sql injection

SecurityVulns

A vulnerability classified as critical has been found in CakePHP up to 5.1.9/5.2.14/5.3.6. This issue affects the function FunctionsBuilder::jsonValue. Performing a manipulation of the argument jsonPath results in sql injection.

This vulnerability is reported as CVE-2026-77635. The attack is possible to be carried out remotely. No exploit exists.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More