Junglewise Threat Intelligence

CVE-2026-15498: sergomanov SmartHomeAdatum SQL injection in Login component

CVE-2026-15498 · Severity: high · CVSS 7.3 · Published 2026-07-12

Executive brief

A security vulnerability exists in the SmartHomeAdatum smart home management software. An attacker can exploit the login system to gain unauthorized access to the underlying database. This could lead to the theft of user credentials, exposure of private home data, or disruption of the smart home system's operations.

Technical details

A SQL injection vulnerability exists in the 'Login' component of sergomanov SmartHomeAdatum. The flaw is located within the 'users.php' file and is triggered by improper sanitization of the 'Login' argument. A remote, unauthenticated attacker can exploit this by sending specially crafted network requests to the application. Successful exploitation allows for the execution of arbitrary SQL commands, potentially leading to data exfiltration or authentication bypass. As the product follows a rolling release model and the vendor has not responded to the disclosure, a formal patch version has not been identified.

Affected products

  • sergomanov SmartHomeAdatum up to cf495353d81b680675eb8d9aa14a318aa45ce12c

Timeline

  • 2026-07-12: disclosed: Vulnerability disclosed via VulDB/NVD
  • 2026-07-12: advisory

References