Junglewise Threat Intelligence

CVE-2026-40847: MB connect line mbCONNECT24 SQL injection in system_tag view

CVE-2026-40847 · Severity: medium · CVSS 6.5 · Published 2026-05-27

Technologies: MB connect line mymbCONNECT24, MB connect line mbCONNECT24. Vendors: MB connect line.

Executive brief

MB connect line mbCONNECT24 and mymbCONNECT24 are remote access platforms used for industrial communication and machine monitoring. A security vulnerability in the system_tag view allows an attacker with low-level access to perform unauthorized database queries. This could lead to a complete exposure of sensitive system data, potentially compromising industrial operations and confidential configuration information.

Technical details

A SQL injection vulnerability exists in the system_tag view of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to and including 2.20.0. The flaw is caused by improper neutralization of special elements within a SQL SELECT command. A remote attacker with low-privileged credentials can exploit this vulnerability over the network without user interaction. Successful exploitation allows the attacker to execute arbitrary SQL queries, leading to a total loss of confidentiality for the underlying database. Users are advised to update to a patched version if available.

Affected products

  • MB connect line mbCONNECT24 <= 2.20.0
  • MB connect line mymbCONNECT24 <= 2.20.0

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: advisory

References

Related threats