Fabcon Europe 26
Conference Sessions
SQL Injection in 2026: Live Exploitation, Modern Risks, and Practical Defenses
SPEAKERS
Mariusz Wójcik
C&F
Piotr Balik
Datumo
ABOUT THE SESSION
SQL Injection is a vulnerability we have known for more than two decades, and by now it should have disappeared from the security landscape. Yet in 2026 it remains one of the most dangerous and frequently exploited attack vectors. Pressure to ship faster, growing application complexity, and AI-assisted code generation are causing old mistakes to reappear in new forms.
In this session, we will walk through a series of live attacks against a vulnerable web application, showing step by step how seemingly small mistakes in query construction can lead to data leakage, unauthorized changes to business data, and privilege escalation. We will also show how this risk evolves in AI-powered applications, especially in text-to-SQL scenarios where user prompts are translated into database queries, creating a new path to prompt-to-SQL injection.
After the live demo, we will cover practical defense techniques that still work in 2026: secure query patterns, parameterization, least-privilege design, and architectural decisions that reduce the blast radius of a successful attack. Attendees will leave with a clear understanding of how SQL Injection still happens, how it is changing in the era of AI, and how to reduce the risk in modern web applications.
MEET THE SPEAKERS
Mariusz Wójcik
C&F
Piotr Balik
Datumo