Junglewise Threat Intelligence

CVE-2026-40836: MB connect line mbCONNECT24 SQL injection in inmessage model

CVE-2026-40836 · Severity: high · CVSS 7.1 · Published 2026-05-27

Technologies: MB connect line mymbCONNECT24, MB connect line mbCONNECT24. Vendors: MB connect line.

Executive brief

MB connect line's remote access platforms, used for industrial communication and IoT management, contain a security flaw in their messaging component. A remote attacker with low-level access can exploit this to read the entire system database or delete certain records. This could lead to the exposure of sensitive configuration data and a partial loss of system integrity.

Technical details

A SQL injection vulnerability exists in the 'inmessage' model of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to and including 2.20.0. The flaw is caused by improper neutralization of special elements within a SQL DELETE command. A remote attacker with low privileges can exploit this vulnerability over the network without user interaction. Successful exploitation allows the attacker to perform unauthorized database queries to read all table data and delete entries within non-critical tables, resulting in a total loss of confidentiality and partial loss of integrity. Users are advised to update to a patched version if available.

Affected products

  • MB connect line mbCONNECT24 <= 2.20.0
  • MB connect line mymbCONNECT24 <= 2.20.0

Timeline

  • 2026-05-27: advisory: VDE-2026-044 published by CERT VDE
  • 2026-05-27: disclosed: CVE-2026-40836 published to NVD

References

Related threats