VYPR
Medium severity6.5NVD Advisory· Published May 27, 2026

CVE-2026-40846

CVE-2026-40846

Description

An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the system view due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An unauthenticated SQL injection in mbCONNECT24/mymbCONNECT24 allows a low-privileged remote attacker to read sensitive database data, leading to total loss of confidentiality.

Vulnerability

An unauthenticated SQL injection vulnerability exists in the system view of MB connect line's mbCONNECT24 and mymbCONNECT24 products. The flaw is caused by improper neutralization of special elements used in a SQL SELECT command. An attacker with low privileges can exploit this vulnerability remotely. Affected versions have not been explicitly listed in available references, but the advisory (VDE-2026-044) covers all mbCONNECT24/mymbCONNECT24 versions [1].

Exploitation

A low-privileged remote attacker can send a crafted request to the affected system view, injecting SQL commands through an unsanitized input field. No prior authentication is required, and no user interaction is necessary. The attacker does not need any special network position beyond being able to reach the vulnerable endpoint [1].

Impact

Successful exploitation leads to a total loss of confidentiality. The attacker can read arbitrary data from the database, including sensitive information such as credentials or configuration data. The impact is limited to disclosure; integrity and availability are not directly compromised [1].

Mitigation

As of the publication date (2026-05-27), no fixed version has been announced. The vendor has not provided workarounds in the available references. Users are advised to monitor the vendor’s advisory page for updates and restrict network access to the affected systems where possible [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.