Junglewise Threat Intelligence

CVE-2026-40814: MB connect line mbCONNECT24 SQL injection in dataapi.php

CVE-2026-40814 · Severity: high · CVSS 7.5 · Published 2026-05-27

Technologies: MB connect line mymbCONNECT24, MB connect line mbCONNECT24. Vendors: MB connect line.

Executive brief

MB connect line mbCONNECT24 and mymbCONNECT24, platforms used for remote access and industrial monitoring, are affected by a security flaw that allows unauthorized access to their internal databases. An attacker can exploit this to steal sensitive information without needing a username or password. This could lead to a total loss of data confidentiality, potentially exposing industrial configurations or customer information.

Technical details

A SQL injection vulnerability exists in the '_mb24confi_getTagAlarm' function within the 'dataapi.php' file of MB connect line mbCONNECT24 and mymbCONNECT24. The issue stems from improper neutralization of special elements in a SQL SELECT command, allowing an unauthenticated remote attacker to execute arbitrary SQL queries via the network. Successful exploitation enables the attacker to read sensitive data from the database, resulting in a total loss of confidentiality. The vulnerability affects firmware versions up to and including 2.20.0. Users are advised to contact the vendor for patch information or upgrade to a secure version if available.

Affected products

  • MB connect line mbCONNECT24 <= 2.20.0
  • MB connect line mymbCONNECT24 <= 2.20.0

Timeline

  • 2026-05-27: disclosed: Initial advisory publication by CERT VDE
  • 2026-05-27: advisory: NVD publication of CVE-2026-40814

References

Related threats