CVE-2026-79752 is an SQL injection vulnerability in CakePHP FunctionsBuilder methods: cast, extract, datePart, and dateAdd. Affected releases incorporate caller-supplied data type, date-part, or interval-unit values into generated SQL as unescaped structural fragments. Applications that pass untrusted input to these parameters can enable attacker-controlled SQL injection. Affected versions are CakePHP releases before 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, as applicable to the deployed release branch.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This eight-file repository is a self-contained, loopback-only demonstration for CVE-2026-79752, a CWE-89 SQL-injection issue in CakePHP Database FunctionsBuilder methods. Its primary executable, CVE-2026-79752-Abraxas-Labs.py, is a Python HTTP client hard-coded to 127.0.0.1:8088. It performs a baseline GET request and then sends a crafted type query parameter designed to exploit unsafe interpolation of a cast data type into generated SQL. It evaluates the response for the POCWitness79752 marker and UNION SELECT text rather than providing shell execution, persistence, or external-network functionality. The lab consists of a PHP 8.2 Apache Docker image, Compose configuration bound exclusively to 127.0.0.1:8088, Composer dependencies pinned to cakephp/database 5.2.13, and lab/lab-www/index.php. The PHP application creates /tmp/lab79752.sqlite, initializes notes(id, body), inserts POCWitness79752 when empty, and directly passes $_GET['type'] into $q->func()->cast('body', $type). This is the vulnerable source-to-sink path that makes a structural SQL fragment attacker-controlled. The intended impact is unauthorized SQL execution and data disclosure or modification subject to database privileges. The repository does not contain a reverse shell, credential theft mechanism, persistence component, or scanning logic; it is an operational, hard-coded lab PoC.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A SQL injection vulnerability in CakePHP FunctionsBuilder methods when attacker-controlled input is passed to the data type, date-part, or date-unit parameters. It affects the cakephp/cakephp and cakephp/database Packagist packages.
A critical CakePHP SQL-injection vulnerability in FunctionsBuilder::cast, ::extract, ::datePart, and ::dateAdd. Applications that pass untrusted input to affected structural parameters may expose database confidentiality, integrity, and availability, depending on database privileges.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.