CVE-2026-42031 affects CKAN, the open-source data management system used for data hubs and portals. In CKAN versions prior to 2.10.10 and prior to 2.11.5, the datastore_search_sql functionality contains an SQL injection flaw. An attacker can supply crafted input to datastore_search_sql and cause unintended SQL execution against the backing PostgreSQL database. According to the advisory, exploitation can expose private CKAN resources and PostgreSQL system information, making this both an injection issue and an authorization bypass affecting data confidentiality.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
datastore_search_sql. The documented impact is unauthorized access to private resources stored or exposed through CKAN's DataStore and disclosure of PostgreSQL system information. Available information indicates high confidentiality impact, with limited integrity impact noted in the associated CVSS v4 metadata; no specific availability impact is documented in the provided content.If you can’t patch tonight, do this now.
ckan.datastore.sqlsearch.enabled = false. The advisory notes this feature is disabled by default. Where operationally necessary, further restrict access to the functionality using an IAuthFunctions plugin to limit who can invoke it.Patch, then assume compromise.
datastore_search_sql functionality.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This six-file repository is a standalone Python, single-threaded scanner/exploitation utility claiming to target CVE-2026-42031 in CKAN DataStore. Its primary entry point, scanner.py, uses requests with a dedicated CVE scanner User-Agent, accepts individual targets or targets loaded from a text file, and creates local results/report directories. It sends URL-encoded PostgreSQL ts_rewrite-based SQL payloads to CKAN's datastore_search_sql action. The eight embedded queries enumerate the database name and current user; public-table count and sample names; all and non-system database names; PostgreSQL server version; and schemas. README documentation additionally advertises CSV dumping of up to 100 rows per table and automatic JSON/TXT reporting. config.json duplicates the query set and supplies timeout, retry, delay, output, and User-Agent settings, although scanner.py also contains its own hard-coded configuration and query definitions. requirements.txt lists requests, colorama, tabulate, and python-dateutil. No fixed remote target, command-and-control host, reverse shell, or destructive command is present; targets are supplied by the operator.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A SQL injection vulnerability in CKAN's datastore_search_sql function that can allow attackers to access private resources and PostgreSQL system information.
Unknown
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.