Junglewise Threat Intelligence

CVE-2026-40841: MB connect line mbCONNECT24 SQL injection in getProjectTags

CVE-2026-40841 · Severity: medium · CVSS 6.5 · Published 2026-05-27

Technologies: MB connect line mymbCONNECT24, MB connect line mbCONNECT24. Vendors: MB connect line.

Executive brief

MB connect line mbCONNECT24 and mymbCONNECT24 are remote service platforms used for industrial communication and remote maintenance. A security vulnerability allows a user with low-level access to bypass security controls and access sensitive information from the underlying database. This could lead to a total loss of confidentiality for stored project data and system configurations.

Technical details

A SQL injection vulnerability exists in the getProjectTags function of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to and including 2.20.0. The issue stems from improper neutralization of special elements within a SQL SELECT command (CWE-89). A remote attacker with low-level privileges can exploit this flaw over the network without user interaction. Successful exploitation allows the attacker to execute arbitrary SQL queries, resulting in the unauthorized retrieval of sensitive information from the database. The vulnerability is addressed in firmware versions newer than 2.20.0.

Affected products

  • MB connect line mbCONNECT24 <=2.20.0
  • MB connect line mymbCONNECT24 <=2.20.0

Timeline

  • 2026-05-27: disclosed: Advisory published by CERT VDE and NVD

References

Related threats