Description
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Ankara Hosting Site Management Panel allows SQL Injection.

This issue affects Site Management Panel: through 15062026.
Published: 2026-08-31
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of special elements used in an SQL command creates a vulnerability that allows an attacker to inject arbitrary SQL statements. This can lead to unauthorized read, modification, or deletion of database data and may allow privilege escalation within the application. The weakness is a classic SQL Injection (CWE‑89).

Affected Systems

The vulnerability affects Ankara Hosting's Site Management Panel, all releases through the version marked 15062026. No other products or issuers are currently reported to be impacted.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog. The attack vector is likely through the web interface of the Site Management Panel and probably requires authenticated access to the panel, though the description does not explicitly state the authentication requirement. Based on the listed vulnerability type, exploitation would involve crafting malicious input to a vulnerable query without proper parameterization or escaping.

Generated by OpenCVE AI on August 31, 2026 at 14:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Ankara Hosting Site Management Panel update that removes the vulnerable query handling
  • If a patch is not immediately available, restrict external access to the panel using network segmentation or a firewall and enforce strong authentication
  • Configure the underlying database to run with the least privileges necessary, and consider implementing a web application firewall rule set to block typical SQL injection payload patterns

Generated by OpenCVE AI on August 31, 2026 at 14:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Ankara Hosting Site Management Panel allows SQL Injection. This issue affects Site Management Panel: through 15062026.
Title SQLi in Ankara Hosting's Site Management Panel
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-31T14:20:50.157Z

Reserved: 2026-04-09T07:53:25.006Z

Link: CVE-2026-5956

cve-icon Vulnrichment

Updated: 2026-08-31T14:20:46.499Z

cve-icon NVD

Status : Received

Published: 2026-08-31T13:18:22.740

Modified: 2026-08-31T15:17:36.403

Link: CVE-2026-5956

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T14:45:04Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')