Junglewise Threat Intelligence

CVE-2026-81673: TOOOLS iSquad SQL injection in setVisita endpoint

CVE-2026-81673 · Severity: info · CVSS 9.3 · Published 2026-08-27

Technologies: TOOOLS iSquad. Vendors: TOOOLS.

Executive brief

iSquad is a cross-platform sports analytics platform used by organizations to manage teams, analyze performance, and track fan engagement through visit tracking. A SQL injection vulnerability in the visit tracking API endpoint allows attackers to manipulate or corrupt analytics records, potentially affecting the accuracy of business intelligence, fan metrics, and decision-making for sports management teams.

Technical details

This is a SQL injection vulnerability (CWE-89) in the '/ws/apitribuna/setVisita' endpoint of TOOOLS iSquad. The id_video and id_ambito parameters are directly concatenated into MariaDB SQL queries without validation or sanitization. The vulnerability is remotely exploitable over the network with no authentication required. An attacker can inject arbitrary SQL syntax to disrupt query execution, expose database error messages, and potentially manipulate visit tracking records and analytics integrity. The vendor (TOOOLS) has patched this vulnerability; fixes were deployed to all production instances by July 22, 2026, and no action is required by end users.

Affected products

  • TOOOLS iSquad prior to July 22, 2026

Timeline

  • 2026-08-27: disclosed: Coordinated disclosure via INCIBE-CERT
  • 2026-07-22: patched: Fixes deployed to all production instances

References

Related threats