SQL Injection Vulnerability in Vulnerable Product from Vendor Company
CVE-2026-40846

7.1HIGH

Key Information:

Vendor
CVE Published:
27 May 2026

What is CVE-2026-40846?

A remote attacker with low privileges can exploit an unauthenticated SQL Injection vulnerability due to inadequate handling of special characters within SQL SELECT commands. This vulnerability may lead to unauthorized data access, resulting in a significant compromise of sensitive information and potential loss of confidentiality.

Affected Version(s)

mbCONNECT24 0.0.0 <= 2.20.0

mbCONNECT24 2.20.0

mymbCONNECT24 0.0.0 <= 2.20.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.