Executive brief
Adam Retail Automation Ltd. MobilMen 20T, a retail automation solution, contains a critical security flaw that allows unauthorized individuals to manipulate its database. An attacker could use this vulnerability to steal sensitive business data, modify records, or disrupt retail operations. There is currently no known fix as the vendor has not responded to reports of the issue.
Technical details
A SQL injection vulnerability (CWE-89) exists in Adam Retail Automation Ltd. MobilMen 20T due to improper neutralization of special elements used in SQL commands. The flaw is exploitable over the network without authentication (AV:N/AC:L/PR:N/UI:N), allowing an attacker to execute arbitrary SQL queries against the backend database. This can lead to full compromise of data confidentiality, integrity, and availability. The vulnerability affects versions from v3 through 10072026; as of the disclosure date, the vendor has not provided a patch or responded to notifications.
Affected products
- Adam Retail Automation Ltd. MobilMen 20T v3 through 10072026
Timeline
- 2026-07-10: disclosed
- 2026-07-10: advisory: Advisory published by TR-CERT (USOM)