Unpatched SQLi Hits Raytha CMS OData Filter
Raytha CMS 1.5.2 has an unauthenticated SQL injection flaw in its OData filter parsing that can lead to full PostgreSQL database compromise.
CERT Polska coordinated the disclosure of CVE-2026-12076, a SQL injection vulnerability in Raytha CMS affecting the OData filter parsing pipeline. The flaw allows a remote, unauthenticated attacker to inject arbitrary SQL statements against the backend PostgreSQL database, potentially resulting in full database compromise including extraction of stored credentials.
The vulnerability has been confirmed in Raytha CMS version 1.5.2; other versions may also be affected but could not be verified as vendor contact attempts were unsuccessful, meaning no patch is currently available. Organizations running Raytha CMS should treat any OData filter input as untrusted and consider additional mitigations such as web application firewalls or restricting external access until a fix is released. The report credits researcher Arkadiusz Marta for responsible disclosure through CERT Polska's coordinated vulnerability disclosure process.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/06/CVE-2026-12076
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free