Junglewise Threat Intelligence

CVE-2026-40843: MB connect line mbCONNECT24 SQL injection in alarming view

CVE-2026-40843 · Severity: medium · CVSS 6.5 · Published 2026-05-27

Technologies: MB connect line mymbCONNECT24, MB connect line mbCONNECT24. Vendors: MB connect line.

Executive brief

MB connect line industrial remote access platforms are affected by a security flaw in the alarming view component. A remote attacker with low-level user permissions can exploit this to gain unauthorized access to the underlying database. This could lead to the exposure of sensitive system information and a total loss of data confidentiality.

Technical details

A SQL injection vulnerability exists in the alarming view component of mbCONNECT24 and mymbCONNECT24 firmware versions 2.20.0 and earlier. The flaw is caused by improper neutralization of special elements within a SQL SELECT command. A remote attacker with low-privileged credentials can inject malicious SQL queries over the network without user interaction. Successful exploitation allows the attacker to read sensitive information from the database, resulting in a total loss of confidentiality. The vulnerability is tracked as CVE-2026-40843 and was disclosed by CERT VDE.

Affected products

  • MB connect line mbCONNECT24 <= 2.20.0
  • MB connect line mymbCONNECT24 <= 2.20.0

Timeline

  • 2026-05-27: disclosed: Initial advisory published by CERT VDE
  • 2026-05-27: advisory: NVD record published

References

Related threats