CVE-2026-18859
7.3 HIGHPublished 2026-08-05 · Updated 2026-08-05
AI risk analysis
- Summary
- The vulnerability allows for SQL injection through manipulation of the keyid argument in the logindojojs file, enabling remote attackers to exploit it for unauthorized access or data theft.
- Exploitability
- Exploitation is moderately difficult requiring knowledge of the specific argument and potential database structure; however, public availability of similar exploits may ease this process.
- Blast radius
- If exploited, the vulnerability could lead to significant data breaches or system compromise affecting users and potentially impacting organizational operations.
- Prioritized remediation
- Update ESAFENET CDG to the latest version immediately to patch the known vulnerability.
sql-injectionremote-exploitweb-app
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of the file /CDGServer3/ukey/usbkey;logindojojs. Such manipulation of the argument keyid leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Weaknesses
CWE-74, CWE-89
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.