Junglewise Threat Intelligence

CVE-2026-40842: MB connect line mbCONNECT24 SQL injection in getWidgetTags

CVE-2026-40842 · Severity: medium · CVSS 6.5 · Published 2026-05-27

Technologies: MB connect line mymbCONNECT24, MB connect line mbCONNECT24. Vendors: MB connect line.

Executive brief

MB connect line mbCONNECT24 and mymbCONNECT24, platforms used for remote maintenance and industrial communication, are affected by a security vulnerability. A remote attacker with low-level user privileges can exploit this flaw to access sensitive information stored in the system's database. This could lead to a total loss of confidentiality for customer data and system configurations.

Technical details

A SQL injection vulnerability exists in the getWidgetTags function of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions 2.20.0 and earlier. The issue stems from improper neutralization of special elements within a SQL SELECT command (CWE-89). A remote attacker with low-privileged credentials can exploit this vulnerability over the network without user interaction. Successful exploitation allows the attacker to execute arbitrary SQL queries against the backend database, potentially resulting in the unauthorized extraction of all stored data. The vulnerability is addressed in versions newer than 2.20.0.

Affected products

  • MB connect line mbCONNECT24 <= 2.20.0
  • MB connect line mymbCONNECT24 <= 2.20.0

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: advisory

References

Related threats