Junglewise Threat Intelligence

CVE-2026-9668: ZTE ICCP SQL injection authentication bypass

CVE-2026-9668 · Severity: medium · CVSS 6.3 · Published 2026-08-26

Vendors: Zte.

Executive brief

ZTE's ICCP (Intelligent Customer Care Platform) is a customer-facing service management system. An attacker with valid user credentials can craft malicious SQL statements to bypass authentication checks and execute arbitrary database queries, potentially compromising customer data, service availability, and system integrity.

Technical details

This is a SQL injection vulnerability in ZTE ICCP's authentication logic that allows an authenticated attacker to construct malicious SQL queries. The vulnerability requires the attacker to possess legitimate user credentials to reach the affected code path. Once exploited, it enables arbitrary SQL query execution, leading to potential data exfiltration, authentication bypass, and database manipulation. The low exploitation threshold and wide impact scope make this a significant risk despite the medium CVSS score. Patches are available from ZTE.

Affected products

  • ZTE ICCP <UNKNOWN>

Timeline

  • 2026-08-26: disclosed
  • other: CVE-2026-9668 assigned

References