{"id":"CVE-2026-18859","published":"2026-08-05T01:16:44.947","lastModified":"2026-08-05T15:16:45.150","description":"A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of the file /CDGServer3/ukey/usbkey;logindojojs. Such manipulation of the argument keyid leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.","cvssScore":7.3,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","cwes":["CWE-74","CWE-89"],"vendors":[],"products":[],"references":[{"url":"https://ucn9h68n9289.feishu.cn/docx/LHkddOv7Jo6quTxlJKZcf8gfnOe?from=from_copylink","tags":[]},{"url":"https://vuldb.com/cve/CVE-2026-18859","tags":[]},{"url":"https://vuldb.com/submit/858586","tags":[]},{"url":"https://vuldb.com/vuln/385869","tags":[]},{"url":"https://vuldb.com/vuln/385869/cti","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The vulnerability allows for SQL injection through manipulation of the keyid argument in the logindojojs file, enabling remote attackers to exploit it for unauthorized access or data theft.","exploitability":"Exploitation is moderately difficult requiring knowledge of the specific argument and potential database structure; however, public availability of similar exploits may ease this process.","blast_radius":"If exploited, the vulnerability could lead to significant data breaches or system compromise affecting users and potentially impacting organizational operations.","remediation":"Update ESAFENET CDG to the latest version immediately to patch the known vulnerability.","tags":["sql-injection","remote-exploit","web-app"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T07:00:40.620Z"}}