{"affected":[{"affectedData":[{"product":"v6","vendor":"cubecart","versions":[{"status":"affected","version":"< 6.7.5"}]}],"source":"security-advisories@github.com"}],"cveTags":[],"descriptions":[{"lang":"en","value":"CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator-controlled tablename values into ALTER TABLE, CHECK TABLE, and ANALYZE TABLE statements without validating the identifiers or escaping embedded backticks. An authenticated administrator can terminate the quoted identifier with a closing backtick and introduce attacker-controlled structural SQL, potentially compromising database confidentiality, integrity, and availability within the application's database privileges. This issue is fixed in version 6.7.5."}],"id":"CVE-2026-54646","lastModified":"2026-09-23T19:43:31.933","metrics":{"cvssMetricV31":[{"cvssData":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"exploitabilityScore":1.2,"impactScore":5.9,"source":"security-advisories@github.com","type":"Secondary"}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"id":"CVE-2026-54646","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","timestamp":"2026-09-18T17:24:18.009613Z","version":"2.0.3"}}]},"published":"2026-09-17T22:17:02.570","references":[{"source":"security-advisories@github.com","url":"https://github.com/cubecart/v6/blob/6.7.5/admin/sources/release_notes/6.7.5.inc.php"},{"source":"security-advisories@github.com","url":"https://github.com/cubecart/v6/commit/fc08d55628191969f2345d06d862df316f7d44d3"},{"source":"security-advisories@github.com","url":"https://github.com/cubecart/v6/releases/tag/6.7.5"},{"source":"security-advisories@github.com","url":"https://github.com/cubecart/v6/security/advisories/GHSA-qcx6-cg43-ffmx"}],"sourceIdentifier":"security-advisories@github.com","vulnStatus":"Deferred","weaknesses":[{"description":[{"lang":"en","value":"CWE-89"}],"source":"security-advisories@github.com","type":"Secondary"}]}