Junglewise Threat Intelligence

CVE-2026-40837: MB connect line mbCONNECT24 SQL injection in getProjectScalings

CVE-2026-40837 · Severity: medium · CVSS 6.5 · Published 2026-05-27

Technologies: MB connect line mymbCONNECT24, MB connect line mbCONNECT24. Vendors: MB connect line.

Executive brief

MB connect line's remote access platforms, used for industrial communication and machine maintenance, contain a security flaw in how they handle database queries. A remote attacker with low-level user permissions can exploit this to access sensitive information stored in the system's database. This could lead to a total loss of data confidentiality, potentially exposing proprietary configuration or operational data.

Technical details

A SQL injection vulnerability exists in the getProjectScalings function of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to and including 2.20.0. The flaw is caused by improper neutralization of special elements within a SQL SELECT command. A remote attacker with low-privileged credentials can exploit this vulnerability over the network without user interaction. Successful exploitation allows the attacker to execute arbitrary SQL queries, leading to a total loss of confidentiality for the data stored in the affected database. The vulnerability is tracked as CVE-2026-40837.

Affected products

  • MB connect line mbCONNECT24 <= 2.20.0
  • MB connect line mymbCONNECT24 <= 2.20.0

Timeline

  • 2026-05-27: disclosed: Advisory published by CERT VDE
  • 2026-05-27: advisory: NVD record published

References

Related threats