Critical severity9.1GHSA Advisory· Published May 13, 2026· Updated May 15, 2026
CVE-2026-42032
CVE-2026-42032
Description
CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed attackers to bypass authorization in order to gain access to private resources and PostgreSQL system information This vulnerability is fixed in 2.10.10 and 2.11.5.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- github.com/advisories/GHSA-cg4x-64p3-x59hghsaADVISORY
- github.com/ckan/ckan/security/advisories/GHSA-cg4x-64p3-x59hnvdMitigationVendor Advisory
- docs.ckan.org/en/2.10/changelog.htmlghsa
- docs.ckan.org/en/2.11/changelog.htmlghsa
- docs.ckan.org/en/2.11/extensions/plugin-interfaces.htmlghsa
- docs.ckan.org/en/2.11/maintaining/configuration.htmlghsa
- nvd.nist.gov/vuln/detail/CVE-2026-42032ghsa
News mentions
0No linked articles in our index yet.