Junglewise Threat Intelligence

CVE-2026-40844: MB connect line mbCONNECT24 SQL injection in dashboard view

CVE-2026-40844 · Severity: medium · CVSS 6.5 · Published 2026-05-27

Technologies: MB connect line mymbCONNECT24, MB connect line mbCONNECT24. Vendors: MB connect line.

Executive brief

MB connect line industrial remote access platforms are vulnerable to a security flaw in their dashboard interface. A remote attacker with low-level user permissions can exploit this to gain unauthorized access to the entire underlying database. This could lead to a complete exposure of sensitive configuration data and system information.

Technical details

A SQL injection vulnerability exists in the dashboard view of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to 2.20.0. The flaw is caused by improper neutralization of special elements within a SQL SELECT command. A remote attacker with low-level authenticated access can inject malicious SQL queries to bypass intended data restrictions. Successful exploitation allows the attacker to read arbitrary data from the database, resulting in a total loss of confidentiality. The vulnerability is reachable over the network without user interaction.

Affected products

  • MB connect line mbCONNECT24 <= 2.20.0
  • MB connect line mymbCONNECT24 <= 2.20.0

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: advisory

References

Related threats