Unrated severityNVD Advisory· Published Jul 28, 2026· Updated Jul 29, 2026
Authenticated SQL Injection Enables Unauthorized Access to Sensitive Information in Ellucian Advance Web and Legacy Advance
CVE-2026-6881
Description
A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field.
This issue affects Advance Web: all versions; Legacy Advance: all versions.
Ellucian CRM Advance is not impacted.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: all versions
- Range: all versions
Patches
Vulnerability mechanics
References
1- labs.sra.io/posts/ellucianmitrethird-party-advisory
News mentions
0No linked articles in our index yet.