CVE-2026-39879

HIGH

SQL injection in syslog-ng SQL destionation driver

Title source: cna
STIX 2.1

Description

Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver has to be manually configured. Fixes are in syslog-ng 4.12, syslog-ng Premium Edition 8.2 and syslog-ng Store Box 7.8

References (1)

Core 1
Core References

Scores

CVSS v3 7.1
EPSS 0.0017
EPSS Percentile 6.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-150
Status published
Products (1)
syslog-ng/syslog-ng < 4.12
Published Jul 20, 2026
Tracked Since Jul 20, 2026