Junglewise Threat Intelligence

CVE-2026-40848: MB connect line mbCONNECT24 SQL injection in tag view

CVE-2026-40848 · Severity: medium · CVSS 6.5 · Published 2026-05-27

Technologies: MB connect line mymbCONNECT24, MB connect line mbCONNECT24. Vendors: MB connect line.

Executive brief

MB connect line industrial remote access platforms are affected by a security vulnerability in the tag view component. A remote attacker with low-level user permissions can exploit this flaw to gain unauthorized access to the underlying database. This could lead to the exposure of sensitive industrial configuration data or customer information, potentially compromising the confidentiality of the entire system.

Technical details

A SQL injection vulnerability exists in the tag view component of MB connect line mbCONNECT24 and mymbCONNECT24 firmware versions up to and including 2.20.0. The flaw is caused by improper neutralization of user-supplied input within SQL SELECT commands (CWE-89). An attacker with low-privileged network access can inject malicious SQL queries to bypass intended access controls. Successful exploitation allows the attacker to read arbitrary data from the database, resulting in a total loss of confidentiality. The vulnerability is reachable over the network and does not require user interaction, though it does require valid low-privileged credentials.

Affected products

  • MB connect line mbCONNECT24 <= 2.20.0
  • MB connect line mymbCONNECT24 <= 2.20.0

Timeline

  • 2026-05-27: disclosed: Advisory published by CERT VDE
  • 2026-05-27: advisory: NVD record published

References

Related threats