Description
An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the alarming view due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
Published: 2026-05-27
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SQL Injection vulnerability in the alarming view arises from improper neutralization of special characters in a SELECT statement. As described, a low‑privileged remote attacker can inject malicious SQL without prior authentication, potentially gaining full access to data stored in the database. Successful exploitation results in a total loss of confidentiality.

Affected Systems

Affected vendors are Helmholz and MB Connect Line. The vulnerable products include myREX24V2, myREX24V2.virtual, mbCONNECT24, and mymbCONNECT24. All are impacted in version 2.20.0, as indicated by the Common Platform Enumeration entries.

Risk and Exploitability

The CVSS score of 7.1 classifies it as a high‑severity flaw with a considerable risk of exploitation. The EPSS score is not available, but the remote attack vector and lack of authentication requirements make the vulnerability attractive to threat actors. Although it is not listed in the CISA KEV catalog, the potential for data compromise warrants urgent attention.

Generated by OpenCVE AI on May 27, 2026 at 10:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch or upgrade to a release issued after version 2.20.0 that resolves the SQL injection in the alarming view.
  • If a patch is not yet available, restrict access to the alarming view to authenticated users only and enforce strict access controls.
  • Implement input validation and output encoding to sanitize all parameters used in SQL SELECT statements, thereby preventing further injection attempts.

Generated by OpenCVE AI on May 27, 2026 at 10:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 27 May 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 27 May 2026 09:00:00 +0000

Type Values Removed Values Added
Description An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the alarming view due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
Title Authenticated SQLi in alarming view
First Time appeared Helmholz
Helmholz myrex24v2
Helmholz myrex24v2.virtual
Helmholz myrex24v2virtual
Mb Connect Line
Mb Connect Line mbconnect24
Mb Connect Line mymbconnect24
Weaknesses CWE-89
CPEs cpe:2.3:a:helmholz:myrex24v2.virtual:*:*:*:*:*:*:*:*
cpe:2.3:a:helmholz:myrex24v2:*:*:*:*:*:*:*:*
cpe:2.3:a:mb_connect_line:mbconnect24:*:*:*:*:*:*:*:*
cpe:2.3:a:mb_connect_line:mymbconnect24:*:*:*:*:*:*:*:*
cpe:2.3:o:helmholz:myrex24v2:2.20.0:*:*:*:*:*:*:*
cpe:2.3:o:helmholz:myrex24v2virtual:2.20.0:*:*:*:*:*:*:*
cpe:2.3:o:mb_connect_line:mbconnect24:2.20.0:*:*:*:*:*:*:*
cpe:2.3:o:mb_connect_line:mymbconnect24:2.20.0:*:*:*:*:*:*:*
Vendors & Products Helmholz
Helmholz myrex24v2
Helmholz myrex24v2.virtual
Helmholz myrex24v2virtual
Mb Connect Line
Mb Connect Line mbconnect24
Mb Connect Line mymbconnect24
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Helmholz Myrex24v2 Myrex24v2.virtual Myrex24v2virtual
Mb Connect Line Mbconnect24 Mymbconnect24
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-05-27T07:58:05.399Z

Reserved: 2026-04-15T09:33:02.613Z

Link: CVE-2026-40843

cve-icon Vulnrichment

Updated: 2026-05-27T11:56:20.218Z

cve-icon NVD

Status : Received

Published: 2026-05-27T09:16:30.490

Modified: 2026-05-27T09:16:30.490

Link: CVE-2026-40843

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-27T13:15:05Z

Weaknesses