CVE -2026-100899 concerns a SQL injection in DevaslanPHP project-management, an open source project management application based on Laravel and Filament. The vulnerability is located in the Timesheet Dashboard and could allow remote intervention in a database query.

The CVE-2026-100899 CVE Feed entry attributes the issue to the whereRaw function in the app/Filament/Widgets/Timesheet/MonthlyReport.php file . The filter parameter is reportedly being passed to an SQL query without adequate secure handling.
See also: SourceCodester Online Reviewer: Four SQL injection vulnerabilities
What is CVE-2026-100899 in DevaslanPHP?
The affected part is used to view and edit work time reports. When a filter is embedded in a dynamic query without strict validation or parameterization, a remote user can try a specially crafted value instead of a simple search criterion.
A successful SQL injection does not automatically mean a complete server takeover. The actual impact depends on the application account's permissions on the database, the server configuration, and whether the Timesheet Dashboard is available to untrusted users.
In practice, the assessment should start with the access model of the facility. A dashboard that is only available to internal users has a different risk than an application hosted on a public address and accepting connections from partners or customers. This distinction does not negate the need for remediation, but it helps to properly prioritize measures.
However, the vulnerability is significant because the request could be initiated remotely and involves a function that processes business-use data. If the database contains customer data, work records, or internal notes, a successful query could impact their confidentiality and integrity.

See also: Laravel Socialite: Critical Identity Bypass via Facebook OIDC
Which versions are affected?
According to the same entry, versions 1.2.1, 1.2.2, 1.2.3, 1.2.4 and v2.0.0-beta1 of DevaslanPHP project-management are affected. No specific patched version is mentioned, so administrators should not assume that a simple update within the same series has necessarily addressed the issue.
The report of CVE-2026-100899 is not accompanied by a clear maintenance announcement with upgrade instructions. This increases the importance of checking that each organization should do in their own environment: application version, report table exposure, user permissions, and connection path to the database.
The DevaslanPHP project-management describes the project as an open source project management tool, with features including task boards, reports, and Jira integration. The releases page lists v2.0.0-beta1 as the latest available version of the project.
The publication states that exploit code is available and that the vendor was notified prior to disclosure, with no response recorded. Because this information comes from a third-party listing and not a project datasheet, careful evaluation is needed before any conclusion of active exploitation can be made.

See also: Cloudflare Containers: Security flaw gave access to other people's data
What should administrators do?
Organizations using an affected version should temporarily restrict access to Timesheet Dashboard, especially from the web, and review which accounts can submit filters. In addition, a backup of the current version should be made before any changes are made and recorded.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Until a clear fix is available, the SecNews technical team recommends checking the code for dynamic whereRaw queries, using bound parameters, and limiting the privileges of the base account to the bare minimum. Validation should be done on the server, not just in the user environment.
For CVE-2026-100899, checks should also cover copies in test environments or old installations that remain accessible. Disabling a feature is not enough when the same application exists in a second subdomain or when a root account retains more privileges than necessary.
It is also useful to examine the logs for unusual values in the reporting function, repeated requests with different filter parameters, or database errors that occurred after the affected versions were installed. Findings need to be correlated with time, account, and originating address.
If suspicious logs are found, retain relevant documentation before rebooting or reinstalling. Retaining logs facilitates internal investigation and notification to data protection officers if actual access to information occurs.
CVE -2026-100899 should be treated as an issue that requires immediate investigation, but don't confuse posting a bug report with a confirmed attack. The safest course of action is to isolate the operation, monitor the official project page, and implement a documented fix as soon as it becomes available.
