Junglewise Threat Intelligence

CVE-2026-18198: TAC Information Services GOLDENHORN ONEIT SQL injection

CVE-2026-18198 · Severity: high · CVSS 8.8 · Published 2026-09-04

Executive brief

GOLDENHORN ONEIT is a trade finance and logistics management system used by import/export businesses to process transactions and manage shipments. A SQL injection vulnerability allows attackers to extract or manipulate sensitive business data including customer information, transaction records, and payment details without authentication.

Technical details

This vulnerability is a blind SQL injection flaw in GOLDENHORN ONEIT that fails to properly sanitize user-supplied input before incorporating it into SQL queries. An attacker can exploit this via the application's input fields to execute arbitrary database queries and extract sensitive information, even though error messages are not displayed (blind injection). The vulnerability is network-accessible and requires no authentication. Exploitation allows unauthorized data extraction or potential database manipulation. Patches are available in version Göbeklitepe and later.

Affected products

  • TAC Information Services Internal and External Trade Inc. GOLDENHORN ONEIT before Göbeklitepe

Timeline

  • 2026-09-04: disclosed

References