Junglewise Threat Intelligence

CVE-2025-8587: AKCE Software Technology SKSPro SQL injection

CVE-2025-8587 · Severity: high · CVSS 8.6 · Published 2026-02-02

Technologies: Akceyazilim Skspro. Vendors: Akceyazilim.

Executive brief

AKCE Software Technology's SKSPro software contains a security flaw that allows unauthorized individuals to interfere with its database. SKSPro is a professional management system, and this vulnerability could allow an attacker to view, modify, or delete sensitive information, potentially leading to a complete service outage. This issue affects all versions of the software released through early 2026.

Technical details

A SQL injection vulnerability exists in AKCE Software Technology SKSPro through version 07012026 due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw allows a remote, unauthenticated attacker to send specially crafted queries to the application's database layer. Successful exploitation can lead to unauthorized data retrieval, modification of database records, or a denial-of-service condition by impacting database availability. The vulnerability is exploitable over the network without user interaction.

Affected products

  • AKCE Software Technology R&D Industry and Trade Inc. SKSPro through 07012026

Timeline

  • 2026-02-02: disclosed: Initial disclosure by TR-CERT
  • 2026-02-02: advisory: NVD published the CVE record

References