Junglewise Threat Intelligence

CVE-2026-10731: Nemon Trade Energy SQL injection in twoStepsAuthVerification

CVE-2026-10731 · Severity: info · CVSS 9.3 · Published 2026-06-09

Executive brief

Nemon Trade Energy and Trade Energy CRM, software suites used by electricity and gas suppliers, contained a critical security flaw in their login system. An attacker could bypass security controls to access the underlying database without needing a username or password. This could allow unauthorized individuals to steal customer data, create fake administrative accounts, or disrupt the company's operations.

Technical details

A SQL injection vulnerability exists in Nemon Trade Energy and Trade Energy CRM version 2.95.55. The flaw is located in the 'two_steps_auth_code' parameter processed by the 'twoStepsAuthVerification' function at the '/user-login' endpoint. Because the 2FA functionality is accessible without prior authentication, a remote attacker can send crafted requests to execute arbitrary SQL commands. This can lead to full database enumeration, unauthorized creation of privileged users, data modification, or denial-of-service. The vendor has patched this in their SaaS environment as of May 26, 2026.

Affected products

  • Nemon Trade Energy 2.95.55
  • Nemon Trade Energy CRM 2.95.55

Timeline

  • 2026-05-26: patched: The vulnerability was mitigated centrally by the vendor.
  • 2026-06-08: advisory: Initial advisory published by INCIBE.
  • 2026-06-09: disclosed: CVE-2026-10731 published to NVD.

References