SQL Injection Vulnerability in Pi.Alert Wi-Fi/LAN Intruder Detector
CVE-2026-44886
8.7HIGH
What is CVE-2026-44886?
The Pi.Alert web service, responsible for detecting unauthorized access via Wi-Fi and LAN, contains a SQL injection vulnerability that can be exploited by unauthenticated users. This flaw exists in the devices.php endpoint, where an attacker can manipulate the action parameter to gain unauthorized access to sensitive database information. The vulnerability is present from June 29, 2024, until it is resolved on May 7, 2026. Users are advised to ensure their systems are updated to prevent exploitation as detailed in the security advisory.
Affected Version(s)
Pi.Alert >= 2024-06-29, < 2026-05-07
