Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-51936

Quick assessment

Affected
Zetetic SQLCipher
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Zetetic SQLCipher 4.15.0 之前版本存在 SQL 注入漏洞。该漏洞与 便捷函数相关,该函数可用于将一个已附加数据库的内容复制到另一个数据库中,通常用于在明文数据库和加密数据库之间进行转换。由于需要执行动态模式操作,该函数在运行过程中会临时清除一些防御性限制。 源数据库名称参数处理过程中的一个漏洞使得攻击者可以构造恶意的源数据库名称,从而执行原本会被防御模式阻止的 SQL 语句。这可能导致对 表的直接修改以及数据库损坏。 在 SQLCipher 4.15.0 版本中,已对源数据库名称进行严格验证

CVSS 2.1 · Low

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-51936

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Zetetic SQLCipher before 4.15.0 allows SQL injection. The sqlcipher_export convenience function can be used to copy the contents of one attached database into another. It is most often used to convert between plaintext and encrypted databases. It needs to do dynamic schema manipulation, and thus the function temporarily clears defensive restrictions during operation. A vulnerability in the handling of the source database name parameter made it possible for a caller to supply a crafted source name, which could execute statements that defensive mode would otherwise block. This could allow direct modifications to the sqlite_schema table and database corruption. SQLCipher 4.15.0 now strictly validates the source database name and prevents the bypass.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:L
Source: CVE Program / CVE List V5
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Zetetic SQLCipher 0 ~ 4.15.0 -

II. Public POCs for CVE-2026-51936

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-51936

请登录查看更多情报信息。

Other References for CVE-2026-51936 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-51936

No comments yet


Leave a comment