SQL Injection Vulnerability in Alarming View of Vendor Software
CVE-2026-40843
7.1HIGH
What is CVE-2026-40843?
A low privileged remote attacker could exploit an unauthenticated SQL Injection vulnerability present in the alarming view due to inadequate sanitation of special elements in a SQL SELECT command. This vulnerability may lead to a complete breach of confidentiality, allowing attackers to access sensitive data without proper authorization.
Affected Version(s)
mbCONNECT24 0.0.0 <= 2.20.0
mbCONNECT24 2.20.0
mymbCONNECT24 0.0.0 <= 2.20.0
