Junglewise Threat Intelligence

CVE-2026-40840: MB connect line mbCONNECT24 SQL injection in VerifyCreateLicences

CVE-2026-40840 · Severity: medium · CVSS 6.5 · Published 2026-05-27

Technologies: MB connect line mymbCONNECT24, MB connect line mbCONNECT24. Vendors: MB connect line.

Executive brief

MB connect line's remote access platforms, used for industrial communication and machine maintenance, are affected by a security flaw. A remote attacker with low-level user permissions can exploit this vulnerability to gain unauthorized access to the underlying database. This could lead to a complete exposure of sensitive system information and customer data.

Technical details

A SQL injection vulnerability exists in the VerifyCreateLicences function of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to and including 2.20.0. The flaw is caused by improper neutralization of special elements within a SQL SELECT command. A remote attacker with low-privileged credentials can inject malicious SQL queries via the network. Successful exploitation allows the attacker to read arbitrary data from the database, resulting in a total loss of confidentiality. The vulnerability is tracked as CVE-2026-40840 and was disclosed alongside several other SQLi flaws in the same product line.

Affected products

  • MB connect line mbCONNECT24 <= 2.20.0
  • MB connect line mymbCONNECT24 <= 2.20.0

Timeline

  • 2026-05-27: disclosed: Initial advisory publication by CERT VDE
  • 2026-05-27: advisory: NVD record published

References

Related threats