SQL Injection Vulnerability in NetBotz by Schneider Electric
CVE-2026-13337

5.1MEDIUM

Key Information:

Vendor
CVE Published:
1 September 2026

What is CVE-2026-13337?

A SQL injection vulnerability exists in the NetBotz products from Schneider Electric, allowing an authenticated attacker to inject malicious HQL queries into the database. This risk is present through access via the web service interface or web UI. Proper authentication and input validation mechanisms are crucial to mitigate this type of vulnerability and protect sensitive data within the application.

Affected Version(s)

NetBotz 5 - 750/755 Versions 5.5.2 and prior

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.