CKAN DataStore SQL Search - SQL Injection
CVE-2026-42031
Verified
Description
CKAN, an open-source data management system used for powering open data portals, contains an unauthenticated SQL injection vulnerability in the datastore_search_sql API endpoint.
Severity
High
CVSS Score
9.8
Exploit Probability
2%
Published Date
May 4, 2026
Template Author
theamanrawat
CVE-2026-42031.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-42031
CWE ID:
cwe-89
Remediation Steps
Upgrade CKAN to version 2.10.10 or 2.11.5 or later.