Junglewise Threat Intelligence

CVE-2025-70420: Genesys Latitude SQL injection in backend database

CVE-2025-70420 · Severity: info · CVSS 8.8 · Published 2026-04-21

Executive brief

Genesys Latitude, a debt collection and accounts receivable management software, was reported to have a security flaw that could allow an authorized user to run unauthorized database commands. While initially reported as a critical SQL injection vulnerability, the record was subsequently withdrawn by the issuing authority after further investigation determined it was not a security issue. Organizations using this specific version should be aware of the report but note that it has been officially rejected as a vulnerability.

Technical details

A SQL injection vulnerability (CWE-89) was initially reported in Genesys Latitude v25.1.0.420. The report claimed that unsanitized user-supplied input was concatenated directly into SQL statements, allowing an authenticated attacker with network access to execute arbitrary queries against the backend database. However, the CVE record was later rejected and withdrawn by the CNA (MITRE) because further investigation showed that the behavior did not constitute a security issue. Prior to rejection, CISA-ADP had assigned a CVSS v3.1 score of 8.8.

Affected products

  • Genesys Latitude 25.1.0.420

Timeline

  • 2026-04-21: disclosed: Initial CVE publication
  • 2026-04-22: advisory: CISA-ADP added CVSS and CWE details
  • 2026-06-10: other: CVE record rejected and withdrawn by the CNA