Junglewise Threat Intelligence

CVE-2026-40827: MB connect line mbCONNECT24 SQL injection in _RemoveRequest

CVE-2026-40827 · Severity: medium · CVSS 5.5 · Published 2026-05-27

Technologies: MB connect line mymbCONNECT24, MB connect line mbCONNECT24. Vendors: MB connect line.

Executive brief

MB connect line mbCONNECT24 and mymbCONNECT24, platforms used for remote maintenance and industrial communication, are affected by a security vulnerability. A high-privileged remote attacker can exploit this flaw to read the entire database and delete certain non-critical records. This could lead to a significant exposure of sensitive configuration or operational data and minor disruptions to system integrity.

Technical details

A SQL injection vulnerability exists in the _RemoveRequest function of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to 2.20.0. The flaw is caused by improper neutralization of special elements within a SQL DELETE command. A remote attacker with high privileges can exploit this to perform unauthorized database queries, potentially reading the entire database contents or deleting entries in non-critical tables. The attack is reachable over the network and does not require user interaction, though it does require high-level administrative credentials.

Affected products

  • MB connect line mbCONNECT24 <= 2.20.0
  • MB connect line mymbCONNECT24 <= 2.20.0

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: advisory

References

Related threats