Junglewise Threat Intelligence

CVE-2026-54222: UBB Systems UBB.threads Blind SQL Injection in Members Control Panel

CVE-2026-54222 · Severity: info · CVSS 8.6 · Published 2026-06-18

Technologies: UBB Systems UBB.threads. Vendors: UBB Systems.

Executive brief

UBB.threads, a popular forum and community software, contains a security flaw in its administrative control panel. An attacker with administrative access to the member management section can use this flaw to bypass security controls and directly query the underlying database. This could allow them to steal sensitive information, including user credentials and private forum data.

Technical details

A Blind SQL Injection vulnerability exists in UBB.threads through version 7.7.5 due to insufficient input sanitization within the 'Members' section of the Control Panel. An attacker with high privileges (access to the Control Panel) can manipulate SQL queries using time-based or boolean-based techniques to interact with the underlying database. This flaw allows for the extraction of sensitive data, such as user credentials. The vulnerability is confirmed in version 7.7.5, but other versions are likely affected as vendor contact attempts were unsuccessful and no patch is currently available.

Affected products

  • UBB Systems UBB.threads All versions through 7.7.5

Timeline

  • 2026-06-18: advisory: Advisory published by CERT.PL
  • 2026-06-18: disclosed: Public disclosure via NVD

References

Related threats