Pre-Auth Blind SQL Injection in Userinfo Endpoint for Vendor Product
CVE-2026-32969
7.5HIGH
What is CVE-2026-32969?
An unauthenticated remote attacker can exploit a Pre-Auth blind SQL Injection vulnerability in the userinfo endpoint’s authentication method. This vulnerability arises from inadequate handling of special characters in a SQL SELECT command. If successfully exploited, it could lead to significant breaches of data confidentiality, allowing attackers to manipulate queries and extract sensitive information from the database.
Affected Version(s)
MB connect line mbCONNECT24 0.0.0 <= 2.19.3
mymbCONNECT24 0.0.0 <= 2.19.3
myREX24V2 0.0.0 <= 2.19.3
