PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-62112 Amelia Booking CVE debrief

A SQL injection vulnerability exists in the Amelia plugin versions up to 2.4.9. This issue allows an attacker to inject malicious SQL code, potentially leading to data breaches or other security incidents. The vulnerability has been identified as CVE-2026-62112 and has a CVSS score of 7.6, indicating a high severity level.

Vendor
Amelia Booking
Product
Amelia plugin
CVSS
HIGH 7.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-11
Original CVE updated
2026-09-11
Advisory published
2026-09-11
Advisory updated
2026-09-11

Who should care

Defenders responsible for maintaining the Amelia plugin, as well as security teams and administrators who need to ensure the security of their systems, should be aware of this vulnerability and take steps to mitigate it.

Why it matters

The CVE-2026-62112 SQL injection vulnerability in the Amelia plugin versions up to 2.4.9 requires attention from defenders to prevent potential security incidents. The vulnerability has a high severity level and defenders should prioritize patching or mitigating this issue to prevent exploitation.

  • Potential data breaches or security incidents due to SQL injection attacks
  • Need for patching or mitigation to prevent exploitation
  • Importance of input validation and sanitization to prevent SQL injection attacks
  • Potential impact on system availability and data integrity

Technical summary

The Amelia plugin versions up to 2.4.9 are vulnerable to a SQL injection attack. This vulnerability allows an attacker to inject malicious SQL code, potentially leading to data breaches or other security incidents. The vulnerability has a CVSS score of 7.6, indicating a high severity level.

Defensive priority

Defenders should prioritize patching or mitigating this vulnerability to prevent potential SQL injection attacks.

Recommended defensive actions

  • Patch or update the Amelia plugin to a version that addresses this vulnerability
  • Implement input validation and sanitization to prevent SQL injection attacks
  • Monitor for suspicious activity and implement logging and auditing to detect potential attacks

Evidence notes

The vulnerability was reported by Patchstack and is documented in the CVE Program record and the NVD vulnerability detail page.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-62112 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-62112

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-62112 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-62112

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.