Junglewise Threat Intelligence

CVE-2026-5956: Ankara Hosting Site Management Panel SQL injection

CVE-2026-5956 · Severity: high · CVSS 8.8 · Published 2026-08-31

Executive brief

Ankara Hosting Site Management Panel is a web application used to manage hosting accounts and services. A SQL injection vulnerability allows attackers to bypass authentication, extract sensitive customer data, or manipulate database records without requiring valid credentials, potentially leading to data breaches and service disruption.

Technical details

This vulnerability is a SQL injection (CWE-89) in the Ankara Hosting Site Management Panel, stemming from improper neutralization of special characters in SQL commands. The vulnerability is network-accessible and does not require authentication, allowing unauthenticated attackers to craft malicious SQL queries through user input fields. Successful exploitation allows an attacker to read, modify, or delete database contents, potentially compromising customer accounts and hosting data. A patch is available in versions after 15062026.

Affected products

  • Ankara Hosting Site Management Panel through 15062026

Timeline

  • 2026-08-31: disclosed

References