HIGH
CiviCRM
CVE published 2026-08-11
CVE-2026-72558
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T12:17:41.697Z and has not been modified since then. This SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire database via the contact search RLIKE clause. The clause concatenates a user-supplied value into the SQL query without sanitization, en [truncated]