HIGHCVE-2026-6888Published Modified CNA CSA
CVE-2026-6888: SQL Injection Vulnerability
Successful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to execute arbitrary commands via a specific interface, potentially enabling the attacker to access, modify, or delete sensitive information within the database.
Metrics
- CVSS v3.1
- 7.2
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 8
Affected packages
- Advantech / SaaS Composerprior to version 3.4.17
- Advantech / IoTSuite Growth Linux dockerprior to version 2.2.0
- Advantech / IoTSuite Starter Linux dockerprior to version 2.2.0
- Advantech / IoT Edge Linux dockerprior to version 2.2.0
- Advantech / IoT Edge Windowsprior to version 2.2.0
- Advantech / WebAccess/SCADAprior to version 9.2.3
- Advantech / WebAccess SaaS-Composerprior to version 3.4.17.1
- Advantech / ECOWatch SaaS-Composerprior to version 3.4.17
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HReferences