CVE-2026-42031 carries a CVSS 3.1 base score of 9.8 against CKAN, an open-source data management system used to run data hubs and open-data portals, published by okfn. NVD classifies it as CWE-89 (SQL Injection) and states the vulnerability is fixed in versions 2.10.10 and 2.11.5, meaning releases before those numbers are affected. VulnCheck’s KEV feed reports the CVE as exploited, dated September 10, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2026-42031 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 19, 2026. VulnCheck’s catalog admits vendor and researcher exploitation reporting on broader criteria than CISA’s own listing process has accepted; no Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
NVD’s description names the vulnerable endpoint directly: CKAN’s datastore_search_sql API action, which lets callers run a constrained form of SQL against datasets stored in CKAN’s DataStore extension, fails to properly neutralize special elements in attacker-supplied input before executing it. NVD states the consequence in specific terms — an attacker can use the injection “to gain access to private resources and PostgreSQL system information,” meaning the exposure is not limited to public dataset contents but reaches records and metadata the portal’s access controls are meant to keep private, and potentially details about the underlying PostgreSQL instance itself.
CKAN’s own security advisory, linked from NVD’s record, carries the fix as a version bump to 2.10.10 or 2.11.5 depending on which release line a given deployment tracks — a dual-branch fix pattern typical of a project maintaining both a current and a prior stable series concurrently.
Evidence and confidence
- Medium confidence — the CVSS 9.8 score, the vector (
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), the CWE-89 classification, thedatastore_search_sqlmechanism, and the 2.10.10/2.11.5 fixed-version pair all trace to NVD alone. The exploitation report traces to VulnCheck KEV alone. - Unknown-leaning — exploitation probability. FIRST’s EPSS model scores this CVE 0.01817, 77.6th percentile as of our ingestion — meaningfully above the midpoint of the broader EPSS population, though EPSS is a predictive model, not a confirmation of the VulnCheck report.
No field is in conflict between our two ingested sources. One discrepancy worth flagging rather than resolving: a third-party CVE aggregator surfaced in our SERP research states a CVSS score of 8.3 (HIGH) for this same CVE, against our ingested NVD value of 9.8 (CRITICAL). We report NVD’s figure because NVD is our authoritative source and the aggregator’s basis for a different score isn’t visible to us — a rescoring, a different CVSS version, or an aggregator error could each explain the gap — but the discrepancy itself is worth knowing if you’re reconciling against another vendor’s tooling.
Why this matters
CKAN backs a substantial share of government and institutional open-data portals — it is the software behind many national and municipal data.gov-style sites, not a niche internal tool. A SQL injection reaching “private resources,” in NVD’s own phrasing, on that class of deployment means data a portal operator explicitly chose not to publish becomes reachable to an unauthenticated or low-privileged caller, which is a materially different risk profile than an injection limited to already-public dataset rows.
The severity case for upgrading does not depend on the VulnCheck exploitation report: NVD’s own description states unauthenticated access to private resources and database system information as the outcome, which is sufficient grounds to patch to 2.10.10 or 2.11.5 regardless of catalog status. The KEV listing adds real, if uncorroborated, urgency on top of that.
Frequently Asked Questions
What is CVE-2026-42031?
A CVSS 9.8 SQL injection vulnerability (CWE-89) in CKAN’s datastore_search_sql API action, which NVD states allows attackers to access private resources and PostgreSQL system information in CKAN versions before 2.10.10 and 2.11.5.
Is CVE-2026-42031 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 10, 2026. That report is single-sourced; CISA has not listed this CVE as of our September 19, 2026 ingestion, and we have no independent corroboration. Treat it as reported exploitation, not confirmed.
Which CKAN version fixes this? NVD states the fix ships in 2.10.10 for the 2.10.x line and 2.11.5 for the 2.11.x line. Confirm which release branch your deployment tracks before upgrading.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed. The severity case for patching stands independently.
Why do some trackers list a lower CVSS score for this CVE? Our data, sourced from NVD, records 9.8 (CRITICAL). A third-party aggregator we found during research lists 8.3 (HIGH) for the same CVE ID. We report NVD’s figure as our authoritative source; the source of the discrepancy isn’t visible in our data.
Does authentication reduce the risk here? NVD’s vector records no required privileges and no required user interaction — the vulnerability is described as reachable without authentication.
Severity, vector, weakness classification, mechanism, and fixed-version pair sourced from the National Vulnerability Database record for CVE-2026-42031, which links CKAN’s own GitHub security advisory. Exploitation status and the September 10, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 19, 2026. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.