SQL Injection Vulnerability in dsgvo_contracts View Affecting Vendor Software
CVE-2026-40826
6.9MEDIUM
What is CVE-2026-40826?
An unauthenticated SQL Injection vulnerability in the dsgvo_contracts view of Vendor Software allows high-privileged remote attackers to execute malicious SQL commands. This exploitation can lead to unauthorized access to sensitive data, resulting in a significant compromise of confidentiality. Preventative measures and prompt remediation are critical to safeguarding against such risks.
Affected Version(s)
mbCONNECT24 0.0.0 <= 2.20.0
mbCONNECT24 2.20.0
mymbCONNECT24 0.0.0 <= 2.20.0
