Description
EFence developed by Thinking Software Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.
Published: 2026-09-14
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated remote SQL Injection.
Action: Patch immediately
AI Analysis

Impact

EFence, developed by Thinking Software Technology, contains a SQL Injection flaw that allows an unauthenticated remote attacker to embed arbitrary SQL commands. The vulnerability can be exploited to read contents from the underlying database, potentially exposing sensitive data. This flaw is an instance of CWE-89 and results primarily in data disclosure rather than modification.

Affected Systems

The affected product is Thinking Software Technology’s EFence. All releases prior to 1.2.67 with database version below 57 are vulnerable. Users should update to EFence 1.2.67 or later, which includes the fix.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. Exploit probability is not documented (EPSS not available) and the vulnerability is not in the CISA KEV catalog. Based on the description, the attack vector is remote and requires no authentication. The lack of authentication requirements combined with the potential to expose database content makes this a significant risk for any installation exposed to the network.

Generated by OpenCVE AI on September 15, 2026 at 14:40 UTC.

Remediation

Vendor Solution

Please update to 1.2.67 DB Ver:57 or later


OpenCVE Recommended Actions

  • Upgrade EFence to version 1.2.67 or later, which patches the SQL injection vulnerability.
  • Restrict network access to EFence user interfaces to trusted IP ranges or via firewall rules to limit exposure to unauthenticated remote attacks.
  • Implement input validation and enforce the use of parameterized queries or prepared statements to prevent inadvertent SQL injection, and monitor database logs for anomalous queries.

Generated by OpenCVE AI on September 15, 2026 at 14:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Thinkingsoftware
Thinkingsoftware efence
Vendors & Products Thinkingsoftware
Thinkingsoftware efence

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description EFence developed by Thinking Software Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.
Title Thinking Software Technology|EFence - SQL Injection
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Thinkingsoftware Efence
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-09-14T11:19:46.131Z

Reserved: 2026-09-11T06:14:53.094Z

Link: CVE-2026-89180

cve-icon Vulnrichment

Updated: 2026-09-14T11:13:47.626Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T11:17:05.860

Modified: 2026-09-18T19:15:11.780

Link: CVE-2026-89180

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:45:30Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')