Junglewise Threat Intelligence

CVE-2026-8025: MOSK Information Technologies CBS Platform SQL injection

CVE-2026-8025 · Severity: critical · CVSS 9.8 · Published 2026-06-09

Executive brief

A critical security vulnerability has been identified in the MOSK Information Technologies CBS Platform, a geographic information system. This flaw allows unauthorized individuals to manipulate the underlying database, potentially leading to the theft of sensitive data, alteration of records, or complete loss of service. Because the vendor no longer supports this product, no official security patches will be released, posing a significant long-term risk to organizations still using the software.

Technical details

A SQL injection vulnerability (CWE-89) exists in the MOSK Information Technologies Ltd. CBS Platform due to improper neutralization of special elements used in SQL commands. The flaw is remotely exploitable over the network without authentication (AV:N/AC:L/PR:N/UI:N). An attacker can leverage this to bypass security measures, access or modify sensitive database content, and potentially gain administrative control over the application. The vendor has confirmed the product is no longer supported, meaning no patch is available for versions through 09062026.

Affected products

  • MOSK Information Technologies Ltd. CBS Platform through 09062026

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory: Advisory published by TR-CERT

References