CVE-2026-40906

CRITICAL

Electric: SQL Injection via ORDER BY Parameter in Shape API

Title source: cna
STIX 2.1

Description

Electric is a Postgres sync engine. From 1.1.12 to before 1.5.0, the order_by parameter in the ElectricSQL /v1/shape API is vulnerable to error-based SQL injection, allowing any authenticated user to read, write, and destroy the full contents of the underlying PostgreSQL database through crafted ORDER BY expressions. This vulnerability is fixed in 1.5.0.

Scores

CVSS v3 9.9
EPSS 0.0003
EPSS Percentile 9.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
electric-sql/electric >= 1.1.12, < 1.5.0
Published Apr 21, 2026
Tracked Since Apr 22, 2026