Junglewise Threat Intelligence

CVE-2026-40846: MB connect line mbCONNECT24 SQL injection in system view

CVE-2026-40846 · Severity: medium · CVSS 6.5 · Published 2026-05-27

Technologies: MB connect line mymbCONNECT24, MB connect line mbCONNECT24. Vendors: MB connect line.

Executive brief

MB connect line mbCONNECT24 and mymbCONNECT24, platforms used for remote access and industrial communication, are affected by a security vulnerability. A remote attacker with low-level user permissions can exploit this flaw to gain unauthorized access to the underlying database. This could lead to a complete exposure of sensitive system information and customer data stored within the platform.

Technical details

A SQL injection vulnerability exists in the 'system view' component of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to and including 2.20.0. The flaw is caused by improper neutralization of special elements within a SQL SELECT command (CWE-89). An attacker with low-privileged network access can inject malicious SQL queries to bypass intended access controls. Successful exploitation allows the attacker to read sensitive information from the database, resulting in a total loss of confidentiality. The vulnerability is reachable over the network without requiring user interaction, though it does require valid low-privileged credentials.

Affected products

  • MB connect line mbCONNECT24 <= 2.20.0
  • MB connect line mymbCONNECT24 <= 2.20.0

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: advisory

References

Related threats