CVE-2026-51936
Received Received - Intake

SQL Injection in SQLCipher

Vulnerability report for CVE-2026-51936, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: MITRE

Description

Zetetic SQLCipher before 4.15.0 allows SQL injection. The sqlcipher_export convenience function can be used to copy the contents of one attached database into another. It is most often used to convert between plaintext and encrypted databases. It needs to do dynamic schema manipulation, and thus the function temporarily clears defensive restrictions during operation. A vulnerability in the handling of the source database name parameter made it possible for a caller to supply a crafted source name, which could execute statements that defensive mode would otherwise block. This could allow direct modifications to the sqlite_schema table and database corruption. SQLCipher 4.15.0 now strictly validates the source database name and prevents the bypass.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
zetetic sqlcipher to 4.15.0 (exc)
zetetic sqlcipher 4.15.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a SQL injection flaw in Zetetic SQLCipher versions before 4.15.0. It occurs in the sqlcipher_export function, which copies database contents between plaintext and encrypted databases. The function temporarily disables defensive restrictions to perform schema manipulation. A crafted source database name parameter could bypass these restrictions, allowing direct modifications to the sqlite_schema table and potentially causing database corruption.

Detection Guidance

To detect this vulnerability, check if your SQLCipher version is below 4.15.0. Run 'sqlcipher --version' to verify. If vulnerable, update to 4.15.0 or later. Test for SQL injection attempts by monitoring logs for unexpected schema modifications or database corruption events.

Impact Analysis

This vulnerability requires an existing SQL injection flaw or unrestricted SQL access to exploit. If exploited, it could allow attackers to modify database schemas or corrupt databases. The impact is limited by the low CVSS score of 2.1, indicating a low severity level. Successful exploitation depends on prior access to the database system.

Compliance Impact

This vulnerability could potentially impact compliance with standards like GDPR and HIPAA by allowing unauthorized modifications to database schemas. If exploited, it might lead to unauthorized data access or corruption, violating integrity and confidentiality requirements in these regulations.

Mitigation Strategies

Upgrade SQLCipher to version 4.15.0 or later to address the sqlcipher_export vulnerability. Validate all database names strictly to prevent injection. Review and test the changes in the commit 30842cd for proper validation of source database names.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-51936. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart