{"id":"CVE-2026-42031","aliases":["GHSA-h7j7-3rx6-xvcg","PYSEC-2026-2417"],"title":"CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`","summary":"CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`","severity":"high","vendor":"ckan","product":"ckan","ecosystem":"pip","affected":["ckan < 2.10.10","ckan >= 2.11.0, < 2.11.5"],"patched":["ckan 2.10.10","ckan 2.11.5"],"published":"2026-04-29","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-h7j7-3rx6-xvcg","references":[{"url":"https://github.com/ckan/ckan/security/advisories/GHSA-h7j7-3rx6-xvcg"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42031"},{"url":"https://docs.ckan.org/en/2.10/changelog.html#v-2-10-10-2026-04-29"},{"url":"https://docs.ckan.org/en/2.11/changelog.html#v-2-11-5-2026-04-29"},{"url":"https://docs.ckan.org/en/2.11/extensions/plugin-interfaces.html#ckan.plugins.interfaces.IAuthFunctions"},{"url":"https://docs.ckan.org/en/2.11/maintaining/configuration.html#ckan-datastore-sqlsearch-enabled"},{"url":"https://github.com/ckan/ckan"}],"tags":["osv","pip","exploit-available"],"epss":0.02188,"epssPercentile":0.81658,"ingestedAt":"2026-07-13T18:57:59.024Z","exploits":{"github":1,"githubRepos":["https://github.com/ddrvahandzo90-hue/CVE-2026-42031-SQL-Injection-Scanner"],"nuclei":["CVE-2026-42031"],"checkedAt":"2026-09-26T09:05:43.677Z"},"exploitAvailable":true,"slug":"CVE-2026-42031","body":"## Overview\n\n### Impact\n\nA vulnerability in `datastore_search_sql` allowed attackers to inject SQL in order to gain access to private resources and PostgreSQL system information.\n\n### Patches\nThe issue has been patched in CKAN 2.10.10 and CKAN 2.11.5\n\n### Workarounds\nDisable the DataStore SQL search (`ckan.datastore.sqlsearch.enabled = false`). Note that the SQL search is disabled by default.\n\n### More information\n\nAs stated in the [documentation](https://docs.ckan.org/en/2.11/maintaining/configuration.html#ckan-datastore-sqlsearch-enabled), this action function has protections that offer some safety but are not designed to prevent all types of abuse. Depending on the sensitivity of private data in a project's DataStore and the likelihood of abuse of a consuming site, a developer may choose to disable this action function or restrict its use with a [`IAuthFunctions`](https://docs.ckan.org/en/2.11/extensions/plugin-interfaces.html#ckan.plugins.interfaces.IAuthFunctions) plugin.\n\n### Credits\n\n* Reported by Arvin Shivram of Brutecat Security\n\n## Affected packages\n\n- `ckan < 2.10.10`\n- `ckan >= 2.11.0, < 2.11.5`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `ckan 2.10.10`\n- `ckan 2.11.5`","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":41.3,"likelihood":0.4,"exploitation":12,"ransomware":0},"changes":[{"seq":5189,"id":"CVE-2026-42031","ts":1788887252540,"field":"exploit_available","old":"false","new":"true"},{"seq":4072,"id":"CVE-2026-42031","ts":1788886369016,"field":"exploit_available","old":"true","new":"false"},{"seq":2861,"id":"CVE-2026-42031","ts":1788883035062,"field":"exploit_available","old":"false","new":"true"},{"seq":1890,"id":"CVE-2026-42031","ts":1788882438470,"field":"exploit_available","old":"true","new":"false"},{"seq":987,"id":"CVE-2026-42031","ts":1788881872604,"field":"exploit_available","old":"false","new":"true"}]}