Unauthenticated SQL Injection Vulnerability in MBNetJ Admin Interface
CVE-2026-40830

7HIGH

Key Information:

Vendor
CVE Published:
27 May 2026

What is CVE-2026-40830?

An unauthenticated SQL Injection vulnerability exists in the admin.mbnetj.php file's UpdateParam function. This flaw allows remote attackers with high privileges to exploit improper neutralization of special elements in SQL UPDATE commands. Successful exploitation can enable attackers to read sensitive data from the entire database and alter values in non-critical tables. Consequently, this can lead to significant breaches of confidentiality and integrity.

Affected Version(s)

mbCONNECT24 0.0.0 <= 2.20.0

mbCONNECT24 2.20.0

mymbCONNECT24 0.0.0 <= 2.20.0

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.