Junglewise Threat Intelligence

CVE-2026-18630: TMT Talassoft Industrial Management Software SQL injection

CVE-2026-18630 · Severity: high · CVSS 8.8 · Published 2026-09-01

Technologies: TMT Machine Industry and Trade Ltd. Co Talassoft Industrial Management Software. Vendors: TMT Machine Industry and Trade Ltd. Co.

Executive brief

Talassoft Industrial Management Software is a system used by manufacturing and industrial operations to manage production, inventory, and business processes. The software contains a SQL injection vulnerability that allows attackers to manipulate database queries, potentially leading to unauthorized access to sensitive production data, operational disruption, or data modification without requiring authentication or special privileges.

Technical details

The vulnerability is a classic SQL injection (CWE-89) in Talassoft Industrial Management Software versions 4 through 15. The flaw stems from improper sanitization of user-supplied input before it is used in SQL queries. An attacker can inject arbitrary SQL commands through vulnerable input fields to read, modify, or delete database contents. The attack vector is network-based and does not require authentication. Patches are available in version 16 and later.

Affected products

  • TMT Machine Industry and Trade Ltd. Co Talassoft Industrial Management Software 4 through 15

Timeline

  • 2026-09-01: disclosed

References

Related threats