Executive brief
A critical security flaw has been identified in Xpoda's Password Module, a component used for managing credentials. This vulnerability allows an unauthorized person to bypass security controls and access or modify sensitive database information over the internet. This could lead to a total compromise of user passwords, data theft, or significant disruption to business operations.
Technical details
A SQL injection vulnerability (CWE-89) exists in the Xpoda Password Module due to improper neutralization of special elements used in SQL commands. The flaw is remotely exploitable over the network without any prior authentication or user interaction (AV:N/AC:L/PR:N/UI:N). An attacker can leverage this vulnerability to execute arbitrary SQL queries against the backend database, potentially leading to full data exfiltration, modification, or deletion. The issue affects versions through 11022026, and the vendor reportedly did not respond to early disclosure attempts.
Affected products
- Xpoda Türkiye Information Technology Inc. Password Module through 11022026
Timeline
- 2026-02-09: disclosed: Initial disclosure by TR-CERT (USOM)
- 2026-02-09: advisory: NVD publication date