SQL Injection Vulnerability in Devices Configuration View from Vendor
CVE-2026-40845
7.1HIGH
What is CVE-2026-40845?
An unauthorized remote attacker can exploit a SQL Injection vulnerability present in the devices configuration view. This issue arises from the improper handling of special characters in SQL SELECT commands, allowing attackers to query sensitive data. Successful exploitation could lead to a complete compromise of confidentiality, posing significant risks to the affected systems.
Affected Version(s)
mbCONNECT24 0.0.0 <= 2.20.0
mbCONNECT24 2.20.0
mymbCONNECT24 0.0.0 <= 2.20.0
