CVE-2026-10731
Description
SQL injection in Nemon Trade Energy and CRM (v2.95.55) allows unauthenticated attackers to execute arbitrary SQL queries, leading to data compromise or denial-of-service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
SQL injection in Nemon Trade Energy and CRM (v2.95.55) allows unauthenticated attackers to execute arbitrary SQL queries, leading to data compromise or denial-of-service.
Vulnerability
A SQL injection vulnerability exists in the two_steps_auth_code parameter processed by the twoStepsAuthVerification function within the /user-login endpoint of Nemon Trade Energy and Nemon Trade Energy CRM, version 2.95.55. This vulnerability allows access to the two-factor authentication functionality without prior authentication [1].
Exploitation
Unauthenticated attackers can exploit this vulnerability by sending a crafted request to the /user-login endpoint, targeting the two_steps_auth_code parameter. No specific user interaction or special privileges are required to trigger the vulnerability, as the 2FA functionality can be accessed directly [1].
Impact
Successful exploitation allows attackers to execute arbitrary SQL queries on the backend database. This can lead to database enumeration, the unauthorized creation of privileged users, modification or deletion of critical information, and denial-of-service conditions [1].
Mitigation
The vulnerability was fixed by the Nemon team on May 26, 2026, and is no longer exploitable. As this is a SaaS solution, the fix was applied centrally by Nemon, requiring no action from customers. There is no evidence that the vulnerability was exploited or had any impact on customers or data [1].
AI Insight generated on Jun 9, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
0No linked articles in our index yet.