Junglewise Threat Intelligence

CVE-2026-40824: MB connect line mbCONNECT24 SQL injection in accountstatus view

CVE-2026-40824 · Severity: medium · CVSS 5.5 · Published 2026-05-27

Technologies: MB connect line mymbCONNECT24, MB connect line mbCONNECT24. Vendors: MB connect line.

Executive brief

MB connect line mbCONNECT24 and mymbCONNECT24 are remote access platforms used for industrial communication and maintenance. A vulnerability in the account status component allows a high-privileged user to perform unauthorized database operations. This could lead to the exposure of sensitive system data and unauthorized modification of certain database records.

Technical details

A SQL injection vulnerability exists in the 'accountstatus' view of MB connect line mbCONNECT24 and mymbCONNECT24 via the 'userid' parameter. The root cause is improper neutralization of special elements within a SQL UPDATE command. A remote attacker with high privileges can exploit this flaw to read the entire database and modify values in non-critical tables. The vulnerability is reachable over the network without user interaction, provided the attacker has the necessary administrative credentials. This issue affects firmware versions up to and including 2.20.0.

Affected products

  • MB connect line mbCONNECT24 <= 2.20.0
  • MB connect line mymbCONNECT24 <= 2.20.0

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: advisory

References

Related threats