CVE-2026-62998 Overview
REDAXO is a PHP-based content management system used to build and manage websites. CVE-2026-62998 is an input validation flaw [CWE-20] in the rex_list::getSortColumn() function located in redaxo/src/core/lib/list.php. The function accepts the sort request parameter without verifying that the requested column was registered via setColumnSortable(). An authenticated backend user can inject an escaped but unauthorized ORDER BY identifier into the query built by prepareQuery(). This enables error-based enumeration of columns in joined tables and ordering by unselected sensitive fields such as rex_user.password. The issue is fixed in REDAXO version 5.21.2.
Critical Impact
Authenticated backend users can enumerate database schema information and infer values of sensitive columns, including password hashes stored in rex_user.
Affected Products
- REDAXO CMS core versions prior to 5.21.2
- redaxo/src/core/lib/list.php component using rex_list::getSortColumn()
- Backend installations exposing sortable list views to authenticated users
Discovery Timeline
- 2026-09-23 - CVE-2026-62998 published to NVD
- 2026-09-23 - Last updated in NVD database
Technical Details for CVE-2026-62998
Vulnerability Analysis
The rex_list component renders sortable tables in the REDAXO backend. Developers call setColumnSortable() to whitelist columns that end users may reorder. The vulnerable getSortColumn() implementation returned the raw sort request parameter without checking that whitelist. prepareQuery() then appended the value as an escaped identifier in the ORDER BY clause of the underlying SQL statement. Because the identifier was escaped rather than validated, standard SQL injection was blocked, but the attacker still controlled which column drove the sort. An authenticated backend user could therefore reference any column in any joined table, including columns that were never rendered in the list output.
Root Cause
The root cause is missing authorization on a user-controlled query fragment. getSortColumn() trusted the incoming HTTP parameter and skipped the hasColumnOption($sortColumn, REX_LIST_OPT_SORT) check that would confirm the column had been registered as sortable. This is a classic improper input validation weakness [CWE-20] applied to a SQL identifier context.
Attack Vector
Exploitation requires an authenticated session with access to a backend list view. The attacker manipulates the sort query parameter to reference columns from joined tables, for example rex_user.password. MySQL error responses and observable ordering differences allow the attacker to infer column existence and, over repeated requests, extract character-by-character information about sensitive values through boolean-style or error-based enumeration.
// Patch from redaxo/core commit c44ba52 — validate sort column against sortable whitelist
public function getSortColumn($default = null)
{
if (rex_request('list', 'string') == $this->getName()) {
- return rex_request('sort', 'string', $default);
+ $sortColumn = rex_request('sort', 'string', $default);
+ if ($this->hasColumnOption($sortColumn, REX_LIST_OPT_SORT)) {
+ return $sortColumn;
+ }
}
return $default;
}
// Source: [GitHub Commit c44ba52](https://github.com/redaxo/core/commit/c44ba5206a28427984100c994010f2aaa6703efd)
Detection Methods for CVE-2026-62998
Indicators of Compromise
- HTTP requests to REDAXO backend list endpoints containing sort parameter values that reference columns not exposed in the visible list, such as password, password_hash, or fully qualified names like rex_user.password.
- Repeated backend requests from a single authenticated session iterating through variations of the sort parameter within short time windows.
- Database error entries referencing invalid ORDER BY identifiers correlated with backend user sessions.
Detection Strategies
- Review web server access logs for list and sort parameter pairs and flag sort values that do not match the documented sortable columns for each list.
- Correlate backend session activity with MySQL general or error logs to identify enumeration patterns against rex_user and other sensitive tables.
- Baseline legitimate sort parameter values per list view and alert on deviations.
Monitoring Recommendations
- Ingest REDAXO web server logs and database error logs into a centralized log platform for query and correlation.
- Monitor backend user accounts for anomalous request volume against list endpoints, which suggests scripted enumeration.
- Track failed and slow queries containing ORDER BY clauses tied to REDAXO list pages.
How to Mitigate CVE-2026-62998
Immediate Actions Required
- Upgrade REDAXO core to version 5.21.2 or later, which enforces the sortable column whitelist in getSortColumn().
- Rotate credentials for any backend accounts that may have been exposed, particularly if password hashes could have been enumerated.
- Audit backend user accounts and remove inactive or excessive privileges to reduce the pool of authenticated attackers.
Patch Information
The fix is committed in c44ba5206a28427984100c994010f2aaa6703efd and shipped in the GitHub Release 5.21.2. Technical background is available in GitHub Pull Request #6580 and the GitHub Security Advisory GHSA-4f5f-j737-pm58. The patch adds a hasColumnOption($sortColumn, REX_LIST_OPT_SORT) check before returning the requested sort column.
Workarounds
- Restrict backend access to trusted IP ranges using web server or firewall rules until the upgrade is applied.
- Apply a virtual patch at the reverse proxy or web application firewall that rejects sort parameter values not present in an allowlist of legitimate column names per list endpoint.
- Disable or hide vulnerable list views that expose sortable tables backed by joins to rex_user or other sensitive tables until patched.
# Example WAF rule concept — restrict allowed sort values for REDAXO backend lists
# Reject requests where the 'sort' parameter contains a period (joined-table syntax)
# or references known-sensitive columns.
SecRule ARGS:sort "@rx (\.|password|salt|token|session)" \
"id:1062998,phase:2,deny,status:403,\
msg:'CVE-2026-62998 REDAXO sort parameter enumeration attempt'"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.