HarborGuard / CVE
Back to search
HIGHCVE-2026-32969Published Modified CNA CERTVDE

CVE-2026-32969: Pre-Auth Blind SQLi in userinfo Endpoint

An unauthenticated remote attacker can exploit a Pre-Auth blind SQL Injection vulnerability in the userinfo endpoint’s authentication method due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

Metrics

CVSS v3.1
7.5
Severity
HIGH
Fixed in
Affected Products
4
Affected packages
  • MB connect line / MB connect line mbCONNECT24
    ≤ 2.19.3
  • MB connect line / mymbCONNECT24
    ≤ 2.19.3
  • Helmholz / myREX24V2
    ≤ 2.19.3
  • Helmholz / myREX24V2.virtual
    ≤ 2.19.3
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N