Junglewise Threat Intelligence

CVE-2026-4978: UMAI Vision Traffic Analysis System SQL injection

CVE-2026-4978 · Severity: critical · CVSS 9.8 · Published 2026-07-30

Executive brief

A critical security flaw has been identified in the UMAI Vision Traffic Analysis System, which is used for monitoring and managing traffic data. This vulnerability allows an unauthorized person to manipulate the system's database remotely. If exploited, an attacker could steal sensitive information, modify system records, or cause a complete service outage, potentially disrupting traffic management operations.

Technical details

An SQL injection vulnerability (CWE-89) exists in the UMAI Vision Traffic Analysis System due to improper neutralization of special elements used in SQL commands. The flaw is exploitable over the network without authentication (AV:N/AC:L/PR:N/UI:N), allowing an attacker to execute arbitrary SQL queries. This can lead to unauthorized data retrieval, modification, or deletion, and potentially full system compromise. The issue affects versions 30 through 33 and is addressed in version 34.

Affected products

  • UMAI Vision Traffic Analysis System 30 to 33 (before 34)

Timeline

  • 2026-07-30: disclosed
  • 2026-07-30: advisory: Advisory published by TR-CERT (USOM)

References