Executive brief
EFence is a security application used to protect and manage file uploads and access controls. This SQL injection vulnerability allows unauthenticated attackers to bypass security controls, access file upload functionality without permission, and extract sensitive data from the underlying database—potentially exposing customer information and system configuration details.
Technical details
CVE-2026-80236 is a SQL injection vulnerability in EFence versions 1.2.66 (DB Ver:56) and earlier. The vulnerability resides in the file upload functionality and permits unauthenticated remote attackers to inject malicious SQL queries over the network (no authentication required, no user interaction needed). Attackers can read arbitrary database contents and gain unauthorized access to file upload features. The vendor has released a patch in version 1.2.67 (DB Ver:57) and later.
Affected products
- Thinking Software Technology EFence 1.2.66 (DB Ver:56) and earlier
Timeline
- 2026-08-26: disclosed