Junglewise Threat Intelligence

CVE-2026-40815: MB connect line mbCONNECT24 SQL injection in _mb24api_getUserAccount

CVE-2026-40815 · Severity: high · CVSS 7.5 · Published 2026-05-27

Technologies: MB connect line mymbCONNECT24, MB connect line mbCONNECT24. Vendors: MB connect line.

Executive brief

MB connect line mbCONNECT24 and mymbCONNECT24 are remote service platforms used for industrial communication and remote maintenance. A security vulnerability allows an unauthenticated attacker to access the underlying database, potentially leading to a total loss of confidentiality for sensitive customer and system data. This could expose operational details or user credentials, compromising the security of the remote access infrastructure.

Technical details

A SQL injection vulnerability exists in the _mb24api_getUserAccount function within MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to and including 2.20.0. The flaw is caused by improper neutralization of special elements in a SQL SELECT command. An unauthenticated remote attacker can exploit this by sending crafted network requests to the affected component. Successful exploitation allows the attacker to execute arbitrary SQL queries, resulting in a total loss of confidentiality for the data stored in the database. The vulnerability is part of a larger set of SQLi issues disclosed in VDE-2026-044.

Affected products

  • MB connect line mbCONNECT24 <= 2.20.0
  • MB connect line mymbCONNECT24 <= 2.20.0

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: advisory

References

Related threats