External risk intelligence

CakePHP SQL Injection Vulnerability in FunctionsBuilder

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-79752

The vulnerability exists in CakePHP, a web application framework. Web frameworks are commonly used to build internet-facing web applications and APIs. Since the vulnerable code paths are reachable via user-supplied input to application endpoints, these services are frequently exposed to the public internet in standard deployment patterns.

SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the CakePHP framework could allow attackers to inject malicious SQL code into applications that use it. This could potentially compromise the confidentiality, integrity, and availability of data depending on the database privileges. The main concern is confirming if our applications utilize the affected components.

  • SQL injection vulnerability in CakePHP.
  • Matters for applications using this framework.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker can inject malicious SQL by providing untrusted input to specific parameters within the CakePHP framework. This occurs when the application uses vulnerable functions like `FunctionsBuilder::cast` or `FunctionsBuilder::dateAdd` without properly escaping user-supplied data before incorporating it into SQL queries. Successful injection can lead to unauthorized access, modification, or disruption of database information, depending on the database's permissions.

  • Requires user-supplied input.
  • Triggers via SQL generation functions.
  • Risks data confidentiality, integrity, availability.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, applications that accept untrusted input for specific database functions could allow attackers to inject malicious SQL code. This could affect the confidentiality, integrity, and availability of the database, depending on the application's database privileges.

  • Database queries and data could be manipulated.
  • Untrusted input could be incorporated into SQL statements.
  • Unauthorized access or data alteration may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners and platform teams are likely responsible for addressing this vulnerability, as it affects the CakePHP framework used in web applications. The first practical step is to identify all instances of the affected CakePHP versions within your environment, assess their exposure and criticality, and then coordinate with the accountable teams to plan remediation.

  • Identify affected CakePHP deployments.
  • Verify application reachability and business impact.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is CakePHP and how does it relate to this vulnerability?

CakePHP is a PHP framework used by developers to build web applications by streamlining database interactions and routing. This vulnerability affects specific core components of the framework, specifically the FunctionsBuilder class, which handles the generation of SQL queries. If an application uses these older versions, it may inadvertently construct unsafe database queries when processing user input.

How does CVE-2026-79752 manifest as a weakness?

This is a classic SQL injection flaw, categorized as CWE-89. In simple terms, the framework fails to treat user-provided data as plain text, allowing that input to be interpreted as active SQL commands instead. When functions like cast or dateAdd receive this tainted input, they insert it directly into database queries, potentially granting an attacker control over the resulting database operations.

Does my application automatically trigger this bug?

The vulnerability is not triggered simply by running an older version of CakePHP. It only becomes a risk if your application code explicitly passes untrusted, user-supplied data into the affected FunctionsBuilder methods (cast, extract, datePart, or dateAdd). If your code uses these functions but only passes hard-coded or strictly validated internal values, the specific injection path remains inactive.

Who should prioritize fixing this issue?

Halo Surface Signal indicates that because CakePHP is frequently used to build internet-facing web applications and APIs, this vulnerability is often reachable by external parties. If your application handles public traffic and utilizes the affected framework methods, it should be treated as a priority. Internal-only applications may have a smaller threat surface but remain susceptible to compromised internal actors.

What is the first step to remediate this vulnerability?

Your immediate action should be to audit your codebase to identify if you are using affected versions of CakePHP and if your application passes user input into the identified FunctionsBuilder methods. Once identified, plan to update the framework to the patched versions—4.5.12, 4.6.5, 5.1.9, 5.2.14, or 5.3.7—which contain the necessary fixes to properly handle and escape data before it reaches your database.

References