CRITICAL
Electric: SQL Injection via ORDER BY Parameter in Shape API
Published Apr 21, 2026
10.0
CRITICALCVSS 3.1
EPSS 0.53%
Description
Electric is a Postgres sync engine. From 1.1.12 to before 1.5.0, the order_by parameter in the ElectricSQL /v1/shape API is vulnerable to error-based SQL injection, allowing any authenticated user to read, write, and destroy the full contents of the underlying PostgreSQL database through crafted ORDER BY expressions. This vulnerability is fixed in 1.5.0.
Affected products
-
- Version >= 1.1.12, < 1.5.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Electric-SQL | Electric | n/a |
|
- ≥ 1.1.12 · < 1.5.0
No data.
Red Hat Developer Hub
rhdh/backstage-community-plugin-catalog-backend-module-scaffolder-relation-processor
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Developer Hub | rhdh/backstage-community-plugin-catalog-backend-module-scaffolder-relation-processor | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://access.redhat.com/security/cve/CVE-2026-40906 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2460291 Issue Tracking
- https://github.com/electric-sql/electric/pull/4081 x_refsource_MISCExploitIssue Tracking
- https://github.com/electric-sql/electric/security/advisories/GHSA-h5rg-pxx7-r2hj exploitx_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-40906
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40906.json
- https://www.cve.org/CVERecord?id=CVE-2026-40906
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-40906 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2460291 | Issue Tracking | |
| https://github.com/electric-sql/electric/pull/4081 | x_refsource_MISCExploitIssue Tracking | |
| https://github.com/electric-sql/electric/security/advisories/GHSA-h5rg-pxx7-r2hj | exploitx_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-40906 | ||
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40906.json | ||
| https://www.cve.org/CVERecord?id=CVE-2026-40906 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Apr 21, 2026
Updated Jul 15, 2026
Reserved Apr 15, 2026
Link CVE-2026-40906
CISA Vulnrichment
Updated Apr 22, 2026