Junglewise Threat Intelligence

CVE-2026-40834: MB connect line mbCONNECT24 SQL injection in saveDashboardLayout

CVE-2026-40834 · Severity: high · CVSS 7.1 · Published 2026-05-27

Technologies: MB connect line mymbCONNECT24, MB connect line mbCONNECT24. Vendors: MB connect line.

Executive brief

MB connect line industrial communication platforms are affected by a security vulnerability in the dashboard layout management component. A remote user with low-level access can exploit this flaw to read sensitive information from the entire database or insert unauthorized data into certain tables. This could lead to a significant breach of confidential business or operational data and minor disruptions to system integrity.

Technical details

A SQL injection vulnerability exists in the MB connect line mbCONNECT24 and mymbCONNECT24 platforms within the 'saveDashboardLayout' function of the 'dash_layout.php' file. The issue stems from improper neutralization of special elements used in a SQL INSERT command. A remote attacker with low-privileged credentials can leverage this flaw via the network to execute arbitrary SQL queries. Successful exploitation allows the attacker to extract the full contents of the database (total loss of confidentiality) and modify or insert data into non-critical tables (partial loss of integrity). The vulnerability is present in firmware versions up to and including 2.20.0.

Affected products

  • MB connect line mbCONNECT24 <= 2.20.0
  • MB connect line mymbCONNECT24 <= 2.20.0

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: advisory

References

Related threats