Junglewise Threat Intelligence

CVE-2026-40838: MB connect line mbCONNECT24 SQL injection in getDeviceScalings

CVE-2026-40838 · Severity: medium · CVSS 6.5 · Published 2026-05-27

Technologies: MB connect line mymbCONNECT24, MB connect line mbCONNECT24. Vendors: MB connect line.

Executive brief

MB connect line's remote access platforms, used for industrial communication and machine maintenance, contain a security flaw that could allow an attacker to access sensitive database information. By exploiting this vulnerability, a user with low-level access can bypass security controls to view data they are not authorized to see. This could lead to the exposure of confidential operational data or system configurations.

Technical details

A SQL injection vulnerability exists in the getDeviceScalings function of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to and including 2.20.0. The flaw is caused by improper neutralization of special elements within a SQL SELECT command. A remote attacker with low-level authenticated privileges can exploit this over the network to execute arbitrary SQL queries. Successful exploitation allows the attacker to read sensitive information from the underlying database, resulting in a total loss of confidentiality for the affected data.

Affected products

  • MB connect line mbCONNECT24 <= 2.20.0
  • MB connect line mymbCONNECT24 <= 2.20.0

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: advisory

References

Related threats