A vulnerability classified as critical has been found in Mautic. This impacts the function
getLeadIdsByFieldValueAction of the file LeadBundle/Controller/AjaxController.php of the component Ajax Controller. Performing a manipulation of the argument Field results in sql injection.
This vulnerability is known as CVE-2026-71245. Remote exploitation of the attack is possible. No exploit is available.