Junglewise Threat Intelligence

CVE-2026-40839: MB connect line mbCONNECT24 SQL injection in getComponentScalings

CVE-2026-40839 · Severity: medium · CVSS 6.5 · Published 2026-05-27

Technologies: MB connect line mymbCONNECT24, MB connect line mbCONNECT24. Vendors: MB connect line.

Executive brief

MB connect line's remote access platforms, used for industrial communication and machine maintenance, contain a security vulnerability that could allow an attacker to access sensitive database information. By exploiting this flaw, a user with low-level access can bypass security controls to view confidential data across the entire system. This could lead to the exposure of proprietary configurations or customer information, potentially impacting business operations and reputation.

Technical details

A SQL injection vulnerability exists in the 'getComponentScalings' function of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to and including 2.20.0. The flaw is caused by improper neutralization of special elements within a SQL SELECT command. A remote attacker with low-privileged credentials can exploit this vulnerability over the network without user interaction. Successful exploitation allows the attacker to perform unauthorized database queries, leading to a total loss of confidentiality for the stored data. The vulnerability is tracked as CVE-2026-40839 and was disclosed alongside several other SQLi flaws in the same product suite.

Affected products

  • MB connect line mbCONNECT24 <= 2.20.0
  • MB connect line mymbCONNECT24 <= 2.20.0

Timeline

  • 2026-05-27: disclosed: Initial advisory publication by CERT VDE and NVD.

References

Related threats