Junglewise Threat Intelligence

CVE-2026-18765: Teracity E-OSB SQL injection

CVE-2026-18765 · Severity: critical · CVSS 9.8 · Published 2026-09-01

Executive brief

Teracity E-OSB is a business software platform used for enterprise operations and data management. The product contains a SQL injection vulnerability that allows attackers to execute arbitrary database commands, potentially exposing sensitive business data, modifying records, or disrupting service availability.

Technical details

The vulnerability is a classic SQL injection (CWE-89) caused by improper neutralization of special elements in SQL commands within E-OSB. An attacker can craft malicious input containing SQL metacharacters to manipulate database queries and execute arbitrary SQL commands. The vulnerability affects E-OSB versions before V02.26.07.08.01 and is reachable over the network. No authentication or user interaction is explicitly required based on the critical CVSS score of 9.8. A patch is available in version V02.26.07.08.01 or later.

Affected products

  • Teracity Software Technologies Inc. E-OSB before V02.26.07.08.01

Timeline

  • 2026-09-01: disclosed

References