Executive brief
MB connect line mbCONNECT24 and mymbCONNECT24 are remote access platforms used for industrial communication and machine maintenance. A security vulnerability allows an unauthenticated attacker to access the underlying database, potentially leading to a total loss of confidentiality for sensitive industrial data and system configurations. This could expose customer information or operational details to unauthorized parties.
Technical details
A SQL injection vulnerability exists in the 'sync_data24' task of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to and including 2.20.0. The flaw is caused by improper neutralization of special elements within a SQL SELECT command. An unauthenticated remote attacker can exploit this by sending specially crafted network requests to the affected component. Successful exploitation allows the attacker to execute arbitrary SQL queries, potentially leading to the unauthorized extraction of the entire database. The vulnerability is tracked as CVE-2026-40819 and has been assigned a CVSS v3.1 base score of 7.5.
Affected products
- MB connect line mbCONNECT24 <= 2.20.0
- MB connect line mymbCONNECT24 <= 2.20.0
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory