CVE-2026-31891 is a SQL injection vulnerability in Cockpit CMS affecting version 2.13.4 and earlier when API access is enabled. The issue resides in the MongoLite Aggregation Optimizer, specifically in handling of aggregation queries for the /api/content/aggregate/{model} endpoint. Unsanitized field names are passed into SQL construction, allowing arbitrary SQL injection against the underlying SQLite content database. According to the provided content, the vulnerable path involves toJsonExtractRaw() in lib/MongoLite/Aggregation/Optimizer.php, which did not apply the field-name sanitization already introduced for toJsonPath() in v2.13.3. Successful exploitation allows an attacker with only a valid read-only API key to bypass the _state=1 published-content filter and extract unauthorized data, including unpublished or otherwise restricted content.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
/api/content/aggregate/{model} endpoint, especially from untrusted networks and users. Disable API access if not required. Rotate and tightly control API keys, including read-only keys, because the vulnerability is exploitable with low-privilege credentials. Apply network-layer access controls, reverse-proxy filtering, or WAF rules to limit access to aggregation endpoints. Monitor for suspicious aggregation requests containing malformed or unexpected field names and review logs for anomalous data-access patterns.Patch, then assume compromise.
toJsonPath() to toJsonExtractRaw() in lib/MongoLite/Aggregation/Optimizer.php. If immediate upgrade is not possible, review and backport the vendor fix to the affected optimizer code path.No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.