Description
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection.

This issue affects Trex MES: through 2026-09-29.
Published: 2026-09-30
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Command Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an SQL injection flaw that allows an attacker to inject malicious commands into an SQL query. When the attack is successful, the injected statement can cause the underlying database engine to execute arbitrary SQL, and because the error message mentions Command Line Execution, the attacker can gain the ability to run operating‑system commands on the host. This compromises confidentiality, integrity, and availability by enabling full control over the affected machine.

Affected Systems

Trex Digital Smart Manufacturing Systems Inc. Trex MES is affected for all releases through 2026‑09‑29. No newer versions are known to fix the issue.

Risk and Exploitability

The CVSS base score is 9.8, indicating a critical level of risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw is an SQL injection that can lead to command execution, the likely attack vector is via application input that is processed into an SQL statement. Attackers would need network access to the application, and the vulnerability may require authentication or privileged access depending on how the input is exposed. The combination of a very high CVSS score and the potential for remote code execution represents a significant threat to affected deployments.

Generated by OpenCVE AI on September 30, 2026 at 16:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied security update for Trex MES immediately.
  • If no update is available, restrict the database account used by Trex MES to the minimum privileges required and disable external access to the database from untrusted hosts.
  • Modify the application to use parameterized queries or stored procedures for all database accesses to eliminate the injection point.

Generated by OpenCVE AI on September 30, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection. This issue affects Trex MES: through 2026-09-29.
Title SQL Injection in Trex Digital Manufacturing's Trex MES
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-09-30T15:28:07.132Z

Reserved: 2026-08-04T08:08:46.916Z

Link: CVE-2026-18782

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-30T15:22:30.177

Modified: 2026-09-30T16:18:57.403

Link: CVE-2026-18782

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T16:30:12Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')