SQL Injection Vulnerability in InMessage Model by Vendor
CVE-2026-40836

7.1HIGH

Key Information:

Vendor
CVE Published:
27 May 2026

What is CVE-2026-40836?

An unauthenticated SQL Injection vulnerability in the InMessage model allows low privileged remote attackers to manipulate SQL DELETE commands. This flaw arises from improper handling of special elements, potentially enabling attackers to read the entire database and delete entries from a non-critical table. The exploitation of this vulnerability poses significant risks, including a complete loss of confidentiality and possible impacts on data integrity.

Affected Version(s)

mbCONNECT24 0.0.0 <= 2.20.0

mbCONNECT24 2.20.0

mymbCONNECT24 0.0.0 <= 2.20.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.