Skip to main content

CVE-2026-51936: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Zetetic SQLCipher

0
Low
VulnerabilityCVE-2026-51936cvecve-2026-51936cwe-89
Published: 09/30/2026 (09/30/2026, 00:19:30 UTC)
Source: CVE Database V5
Vendor/Project: Zetetic
Product: SQLCipher

Description

Zetetic SQLCipher before 4.15.0 allows SQL injection. The sqlcipher_export convenience function can be used to copy the contents of one attached database into another. It is most often used to convert between plaintext and encrypted databases. It needs to do dynamic schema manipulation, and thus the function temporarily clears defensive restrictions during operation. A vulnerability in the handling of the source database name parameter made it possible for a caller to supply a crafted source name, which could execute statements that defensive mode would otherwise block. This could allow direct modifications to the sqlite_schema table and database corruption. SQLCipher 4.15.0 now strictly validates the source database name and prevents the bypass.

CVSS v4.0

Score 2.1low

Attack Vector
Local
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
Low
Vuln. Availability
Low
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
Low
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:L

Affected software

Zetetic

SQLCipher

Affected versions
>=0 <4.15.0
GitHub Actionsmore threats →cve
SQLCipher
pkg:github/SQLCipher
Affected versions
>=0 <4.15.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/30/2026, 01:21:53 UTC

Technical Analysis

Zetetic SQLCipher before version 4.15.0 contains an SQL injection vulnerability in the sqlcipher_export function. This function temporarily disables defensive restrictions to perform dynamic schema changes when copying database contents. Due to insufficient validation of the source database name parameter, an attacker can supply crafted input that executes SQL statements normally blocked by defensive mode. This can lead to direct modifications of the sqlite_schema table and database corruption. The vulnerability is addressed in version 4.15.0 by enforcing strict validation of the source database name to prevent bypassing defensive restrictions.

Potential Impact

An attacker with local access and the ability to call sqlcipher_export can exploit this vulnerability to execute unauthorized SQL commands that modify the database schema, potentially corrupting the database. The impact is limited by the requirement for local access and the low CVSS score indicates limited exploitability and impact.

Mitigation Recommendations

Upgrade to SQLCipher version 4.15.0 or later, which includes a fix that strictly validates the source database name parameter to prevent SQL injection. No other mitigation is indicated or required.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
mitre
Date Reserved
2026-06-08T01:02:33.711Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6abc5d2e680226ef6899b9e2

Added to database: 09/30/2026, 00:51:58 UTC

Last enriched: 09/30/2026, 01:21:53 UTC

Last updated: 09/30/2026, 03:03:19 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses