Junglewise Threat Intelligence

CVE-2026-40811: MB connect line mbCONNECT24 SQL injection in ssoabstractservice

CVE-2026-40811 · Severity: high · CVSS 7.5 · Published 2026-05-27

Technologies: MB connect line mymbCONNECT24, MB connect line mbCONNECT24. Vendors: MB connect line.

Executive brief

MB connect line's remote access platforms, used for industrial communication and machine maintenance, contain a security flaw in their single sign-on service. An unauthenticated attacker can exploit this to gain unauthorized access to the underlying database. This could lead to a total loss of confidentiality for sensitive operational data and system configurations.

Technical details

A SQL injection vulnerability exists in the 'ssoabstractservice' component of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to and including 2.20.0. The flaw is caused by improper neutralization of special elements within a SQL SELECT command. An unauthenticated remote attacker can exploit this over the network without user interaction to execute arbitrary SQL queries. Successful exploitation allows the attacker to read sensitive information from the database, resulting in a total loss of confidentiality.

Affected products

  • MB connect line mbCONNECT24 <= 2.20.0
  • MB connect line mymbCONNECT24 <= 2.20.0

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: advisory

References

Related threats