Junglewise Threat Intelligence

CVE-2026-14809: PROG MIS Prog Management System SQL injection

CVE-2026-14809 · Severity: high · CVSS 7.5 · Published 2026-07-06

Executive brief

The Prog Management System by PROG MIS contains a security flaw that allows unauthorized individuals to access its database. By sending specially crafted requests, an attacker can bypass security controls to view sensitive information stored within the system. This could lead to the exposure of confidential business data or personal information.

Technical details

A SQL injection vulnerability (CWE-89) exists in the PROG MIS Prog Management System. The flaw allows an unauthenticated remote attacker to submit malicious SQL queries to the application, which are then executed by the backend database. This vulnerability can be exploited over the network without any user interaction. Successful exploitation enables the attacker to read arbitrary data from the database, potentially compromising sensitive organizational information. Users are advised to contact the vendor for patching information as all versions are currently reported as affected.

Affected products

  • PROG MIS (博格資訊管理顧問) Prog Management System all versions

Timeline

  • 2026-07-06: disclosed: Initial disclosure by TWCERT/CC
  • 2026-07-06: advisory: NVD publication date

References

Related threats