SQL Injection Vulnerability in Raisecom Communication Command and Dispatch Management Platform
CVE-2026-19764
Key Information:
- Vendor
Raisecom
- Vendor
- CVE Published:
- 14 August 2026
Badges
What is CVE-2026-19764?
A SQL injection vulnerability has been discovered in the Raisecom Communication Command and Dispatch Management Platform, specifically affecting the /app/users/getpwd.php file in versions up to 7.6.5. This flaw allows attackers to manipulate the 'sip' argument, potentially leading to unauthorized access to the database. The vulnerability can be exploited remotely, raising concerns about data integrity and system security. Exploits are publicly available, highlighting the need for immediate mitigation. Despite early notification, the vendor has not responded to this critical security issue.
Affected Version(s)
Communication Command and Dispatch Management Platform 7.6.0
Communication Command and Dispatch Management Platform 7.6.1
Communication Command and Dispatch Management Platform 7.6.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
