Junglewise Threat Intelligence

CVE-2026-40835: MB connect line mbCONNECT24 SQL injection in saveObjectFromData

CVE-2026-40835 · Severity: medium · CVSS 6.5 · Published 2026-05-27

Technologies: MB connect line GmbH mymbCONNECT24, MB connect line GmbH mbCONNECT24.

Executive brief

MB connect line industrial remote access platforms are affected by a security vulnerability that could allow an attacker to access sensitive database information. By exploiting a flaw in how the system handles data saving requests, a user with low-level access can bypass security controls to read unauthorized data. This could lead to a total loss of confidentiality for information stored within the management platform.

Technical details

A SQL injection vulnerability exists in the saveObjectFromData function of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to and including 2.20.0. The flaw is caused by improper neutralization of special elements within a SQL SELECT command. A remote attacker with low-privileged credentials can exploit this vulnerability over the network without user interaction. Successful exploitation allows the attacker to execute arbitrary SQL queries, potentially leading to the unauthorized retrieval of the entire database contents. The vulnerability is tracked as CVE-2026-40835 and has been addressed in newer firmware versions.

Affected products

  • MB connect line GmbH mbCONNECT24 <= 2.20.0
  • MB connect line GmbH mymbCONNECT24 <= 2.20.0

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: advisory

References