Junglewise Threat Intelligence

CVE-2026-40821: MB connect line mbCONNECT24 SQL injection in getAccountByID

CVE-2026-40821 · Severity: medium · CVSS 4.9 · Published 2026-05-27

Technologies: MB connect line mymbCONNECT24, MB connect line mbCONNECT24. Vendors: MB connect line.

Executive brief

MB connect line mbCONNECT24 and mymbCONNECT24, which are platforms used for remote access and management of industrial systems, are affected by a security vulnerability. A high-privileged remote attacker can exploit this flaw to gain unauthorized access to the underlying database. This could lead to a total loss of confidentiality for sensitive account information and operational data stored within the system.

Technical details

A SQL injection vulnerability exists in the getAccountByID function of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to and including 2.20.0. The issue stems from improper neutralization of special elements within a SQL SELECT command. While the vulnerability is described as 'unauthenticated' in the summary text, the CVSS metrics and description specify that a high-privileged remote attacker is required to trigger the exploit. Successful exploitation allows an attacker to execute arbitrary SQL queries against the database, potentially resulting in the extraction of all stored data.

Affected products

  • MB connect line mbCONNECT24 <= 2.20.0
  • MB connect line mymbCONNECT24 <= 2.20.0

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: advisory

References

Related threats