PatchSiren cyber security CVE debrief
CVE-2026-51346 StudIP CVE debrief
A SQL Injection vulnerability exists in StudIP versions 6.0.x before 6.0.3 and 5.4.x before 5.4.12. This vulnerability allows a remote attacker to execute arbitrary code and obtain sensitive information via the store() functions. The CVSS score is 9.1, indicating a critical severity. Defenders responsible for StudIP installations, especially in environments where StudIP is used, should assess exposure and prioritize patching or mitigating this vulnerability. The vulnerability is described in the CVE record and NVD vulnerability detail page. The StudIP versions 6.0.x before 6.0.3 and 5.4.x before 5.4.12 are affected. The store() functions are vulnerable to SQL injection attacks. To
- Vendor
- StudIP
- Product
- StudIP
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-17
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-17
- Advisory updated
- 2026-09-09
Who should care
Defenders responsible for StudIP installations, especially in environments where StudIP is used, should assess exposure and prioritize patching or mitigating this vulnerability.
Why it matters
This SQL Injection vulnerability in StudIP allows remote attackers to execute arbitrary code and obtain sensitive information. Defenders responsible for StudIP installations should assess exposure and prioritize patching or mitigating this vulnerability.
- Remote code execution is possible
- Sensitive information disclosure is possible
- Defenders need to verify StudIP versions and patch levels
- Defenders need to restrict access to the store() functions
Technical summary
The SQL Injection vulnerability in StudIP allows a remote attacker to execute arbitrary code and obtain sensitive information via the store() functions. The vulnerability affects StudIP versions 6.0.x before 6.0.3 and 5.4.x before 5.4.12. This vulnerability has a CVSS score of 9.1, indicating critical severity. Defenders should prioritize patching or mitigating this vulnerability as soon as possible, especially in environments where StudIP is used. The vulnerability is described in the CVE record and NVD vulnerability detail page.
Defensive priority
Defenders should prioritize patching or mitigating this vulnerability as soon as possible, especially in environments where StudIP is used.
Recommended defensive actions
- Patch StudIP to version 6.0.3 or later
- Patch StudIP to version 5.4.12 or later
- Restrict access to the store() functions
- Monitor for suspicious activity
Evidence notes
The vulnerability is described in the CVE record and NVD vulnerability detail page. The StudIP versions 6.0.x before 6.0.3 and 5.4.x before 5.4.12 are affected. The store() functions are vulnerable to SQL injection attacks.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-51346 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-51346
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-51346 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-51346
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://gitlab.studip.de/studip/studip/-/releases/v6.0.3
-
Source reference
Unverified legacy reference
URL: https://simon.hilchenba.ch/blog/studip-sql-injection/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.