Junglewise Threat Intelligence

CVE-2025-10970: Kolay Software Talentics blind SQL injection

CVE-2025-10970 · Severity: critical · CVSS 9.8 · Published 2026-02-20

Executive brief

Kolay Software's Talentics platform is vulnerable to a critical security flaw that allows unauthorized individuals to access its underlying database. Talentics is a software solution used for talent management and recruitment processes. An attacker could exploit this vulnerability to steal sensitive employee data, modify records, or disrupt business operations without needing any login credentials.

Technical details

A Blind SQL Injection vulnerability exists in Kolay Software Inc. Talentics through version 20022026 due to improper neutralization of special elements used in SQL commands (CWE-89). The vulnerability is exploitable over the network without authentication (AV:N/AC:L/PR:N/UI:N). An attacker can send crafted SQL queries to the application and observe the response to extract sensitive information from the database, potentially leading to full data exfiltration or unauthorized modification of records. As of the disclosure date, the vendor has not responded to reports, and no patch has been confirmed.

Affected products

  • Kolay Software Inc. Talentics through 20022026

Timeline

  • 2026-02-20: advisory: Initial disclosure by TR-CERT (USOM)
  • 2026-02-20: disclosed: NVD publication date

References