SQL Injection Vulnerability in CTMS by Sunnet
CVE-2026-7489

8.7HIGH

Key Information:

Vendor

Sunnet

Status
Vendor
CVE Published:
2 May 2026

What is CVE-2026-7489?

The CTMS application developed by Sunnet is vulnerable to SQL Injection, which enables authenticated remote attackers to leverage this weakness to execute arbitrary SQL commands. This can lead to unauthorized access, allowing attackers to read sensitive data, modify records, or delete entire database entries. It is critical for users of CTMS to implement adequate security measures to mitigate this risk and protect their data integrity.

Affected Version(s)

CTMS 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.