SQL Injection Affecting github.com/fleetdm/fleet/v4/server/datastore/mysql package, versions >=4.15.0 <4.81.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.3% (22nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about SQL Injection vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-GITHUBCOMFLEETDMFLEETV4SERVERDATASTOREMYSQL-15367353
  • published2 Mar 2026
  • disclosed26 Feb 2026
  • creditfuzzztf

Introduced: 26 Feb 2026

CVE-2026-26186  (opens in a new tab)
CWE-89  (opens in a new tab)

How to fix?

Upgrade github.com/fleetdm/fleet/v4/server/datastore/mysql to version 4.81.0 or higher.

Overview

Affected versions of this package are vulnerable to SQL Injection via the appendOrderByToSelect ORDER BY construction in server/datastore/mysql/mysql.go when processing ListOptions.OrderKey, allowing an attacker with access to the software versions/list endpoint to inject arbitrary expressions and manipulate query execution order or extract data.

Notes:

  • This is only exploitable if the attacker is authenticated and has access to the affected endpoint.
  • According to the maintainer, no direct evidence of reliable data modification or stacked query execution was demonstrated.

References

CVSS Base Scores

version 4.0
version 3.1