{"apiVersion":"1.0","identifier":"CVE-2026-76635","description":"baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows authenticated administrators to inject attacker-controlled table names and configuration values directly into SQL statements across sequence update, CSV export, and table management operations. Attackers can chain a backup restore code injection flaw, where PHP code outside class definitions in schema files executes unconditionally upon loading, to plant malicious table names and trigger error-based SQL injection that retrieves database version, schema contents, and arbitrary data from the PostgreSQL backend.","publishedAt":"2026-08-20T14:17:59","lastModifiedAt":"2026-08-25T15:16:42","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-76635","cvssScore":7.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","epssProbability":0.00353,"riskScore":0.74,"affectedProduct":"baserCMS","affectedVersions":"<5.3.0","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-76635","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-76635","en":"https://www.redsauce.net/en/cves/CVE-2026-76635","fr":"https://www.redsauce.net/fr/cves/CVE-2026-76635","pt":"https://www.redsauce.net/pt/cves/CVE-2026-76635","de":"https://www.redsauce.net/de/cves/CVE-2026-76635","sk":"https://www.redsauce.net/sk/cves/CVE-2026-76635","el":"https://www.redsauce.net/el/cves/CVE-2026-76635"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-76635"}}