Description
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TAC Information Services Internal and External Trade Inc. GOLDENHORN ONEIT allows Blind SQL Injection.

This issue affects GOLDENHORN ONEIT: before Göbeklitepe.
Published: 2026-09-04
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The defect is an improper neutralization of SQL syntax, allowing a blind SQL Injection that can be leveraged by an attacker to read or alter database contents. The nature of the flaw is a classic injection vulnerability (CWE-89), and the remediation is contingent on applying proper input validation or escaping. While the vendor has not specified the precise attack vector, the description indicates that blind injection is feasible, meaning an attacker can obtain information or modify data without seeing direct error messages. The potential impact for a compromised system includes unauthorized data exposure, integrity violations, and possibly further lateral movement if database credentials are leaked.

Affected Systems

TAC Information Services Internal and External Trade Inc. GoldenHorn OneIT is affected. The vulnerability applies to all versions prior to the Göbeklitepe release. No additional version details are provided beyond this boundary.

Risk and Exploitability

The CVSS score of 8.8 categorizes this flaw as High, indicating significant risk to confidentiality, integrity and availability. No EPSS score is available, so we cannot quantify current exploitation probability, but the absence of a KEV listing suggests it has not yet been widely exploited in known exploit kits. The vulnerability is best demonstrated through blind injection, implying it likely requires access to an exposed input endpoint, which could be either internal or external. Given the high score and lack of mitigation, the risk remains considerable until corrective action is implemented.

Generated by OpenCVE AI on September 4, 2026 at 13:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch that resolves the SQL injection flaw in GoldenHorn OneIT.
  • Limit exposure by restricting network access to the affected modules or disabling the vulnerable functionality until the patch is deployed.
  • Review and harden all user input handling, ensuring that parameters are properly escaped or bound to prevent injection, in line with CWE‑89 best practices.
  • Monitor database logs for anomalous SQL activity that may indicate attempted exploitation.

Generated by OpenCVE AI on September 4, 2026 at 13:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Tac Information
Tac Information goldenhorn Oneit
Vendors & Products Tac Information
Tac Information goldenhorn Oneit

Fri, 04 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TAC Information Services Internal and External Trade Inc. GOLDENHORN ONEIT allows Blind SQL Injection. This issue affects GOLDENHORN ONEIT: before Göbeklitepe.
Title SQL Injection in TAC Information's GoldenHorn
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Tac Information Goldenhorn Oneit
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-09-04T13:11:06.574Z

Reserved: 2026-07-29T07:33:40.030Z

Link: CVE-2026-18198

cve-icon Vulnrichment

Updated: 2026-09-04T13:09:27.224Z

cve-icon NVD

Status : Received

Published: 2026-09-04T13:18:15.023

Modified: 2026-09-04T13:18:15.023

Link: CVE-2026-18198

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T15:19:57Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')