Unauthenticated SQL Injection Vulnerability in Dashboard Layout Function by Vendor
CVE-2026-40834

7.1HIGH

Key Information:

Vendor
CVE Published:
27 May 2026

What is CVE-2026-40834?

This vulnerability allows low-privileged remote attackers to exploit an SQL Injection flaw in the saveDashboardLayout function of dash_layout.php. Due to improper handling of input elements in SQL commands, attackers can execute unauthorized SQL queries, which may lead to unauthorized access to the database. This flaw poses significant risks as it could allow attackers to read sensitive data and insert malicious entries into non-critical tables, affecting data confidentiality and integrity.

Affected Version(s)

mbCONNECT24 0.0.0 <= 2.20.0

mbCONNECT24 2.20.0

mymbCONNECT24 0.0.0 <= 2.20.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.