PT-2026-42405 · Netatalk · Netatalk

Arjun Basnet

·

Published

2026-05-21

·

Updated

2026-05-21

·

CVE-2026-44047

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Netatalk versions 3.1.0 through 4.4.2
Description An SQL injection in the MySQL CNID backend allows a remote authenticated attacker to obtain unauthorized access to data, modify data, or cause a denial of service. SQL injection is a type of flaw that allows an attacker to interfere with the queries that an application makes to its database.
Recommendations Update to version 4.4.3.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-44047

Affected Products

Netatalk