PT-2026-40333 · Shelf · Shelf

Published

2026-05-12

·

Updated

2026-05-14

·

CVE-2026-44204

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Shelf versions 1.12 through 1.20.0
Description An issue in the '/assets' route allows authenticated users of any role to execute arbitrary SQL commands and access data from any database table, including information from other organizations. This is caused by a SQL injection in the sortBy query parameter.
Recommendations Update to version 1.20.1. As a temporary workaround, avoid using the sortBy parameter in the '/assets' route.

Exploit

Fix

RCE

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-44204

Affected Products

Shelf