SQL Injection Vulnerability in InMessage Model by Vendor
CVE-2026-40836
7.1HIGH
What is CVE-2026-40836?
An unauthenticated SQL Injection vulnerability in the InMessage model allows low privileged remote attackers to manipulate SQL DELETE commands. This flaw arises from improper handling of special elements, potentially enabling attackers to read the entire database and delete entries from a non-critical table. The exploitation of this vulnerability poses significant risks, including a complete loss of confidentiality and possible impacts on data integrity.
Affected Version(s)
mbCONNECT24 0.0.0 <= 2.20.0
mbCONNECT24 2.20.0
mymbCONNECT24 0.0.0 <= 2.20.0
