Junglewise Threat Intelligence

CVE-2026-7486: Netcad E-İmar SQL injection

CVE-2026-7486 · Severity: critical · CVSS 9.8 · Published 2026-06-09

Executive brief

Netcad E-İmar, a software solution used for city planning and zoning management, contains a critical security flaw. This vulnerability allows an attacker to manipulate the underlying database, potentially leading to the theft of sensitive municipal data, unauthorized modification of records, or a complete shutdown of the service. No special access or user interaction is required for an attacker to exploit this flaw over the internet.

Technical details

A SQL injection vulnerability exists in Netcad E-İmar due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is reachable over the network without authentication (AV:N/AC:L/PR:N/UI:N). An attacker can exploit this to execute arbitrary SQL queries, enabling them to read, modify, or delete data within the database, and potentially gain administrative control over the application. The issue affects versions from 2.10.1.0 up to (but not including) 3.0.2. Users are advised to upgrade to version 3.0.2 or later to mitigate this risk.

Affected products

  • Netcad Software Inc. E-İmar from 2.10.1.0 before 3.0.2

Timeline

  • 2026-06-09: disclosed: Initial publication of the vulnerability details.
  • 2026-06-09: advisory: Advisory published by the Computer Emergency Response Team of the Republic of Turkey.

References