SQL Injection Vulnerability in Borg SPM 2007 by BorG Technology Corporation
CVE-2026-6887

9.3CRITICAL

Key Information:

Vendor
CVE Published:
23 April 2026

What is CVE-2026-6887?

The Borg SPM 2007 software, developed by BorG Technology Corporation, contains a vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL commands. This weakness enables attackers to potentially read, modify, or delete database content, posing severe risks to data integrity and confidentiality. As the product is no longer supported (sales ended in 2008), it is crucial for organizations still using this software to be aware of the security implications and consider alternative solutions.

Affected Version(s)

Borg SPM 2007 0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.