SQL Injection Vulnerability in Product by Vendor
CVE-2026-40839
7.1HIGH
What is CVE-2026-40839?
An unauthenticated SQL Injection vulnerability exists in the getComponentScalings function, primarily due to improper handling of special elements in SQL SELECT commands. This flaw allows a low privileged remote attacker to execute malicious SQL queries, potentially leading to a complete compromise of data confidentiality. Affected users should act promptly to remediate this issue to prevent unauthorized data access.
Affected Version(s)
mbCONNECT24 0.0.0 <= 2.20.0
mbCONNECT24 2.20.0
mymbCONNECT24 0.0.0 <= 2.20.0
