← Back to search

CVE-2026-18859

7.3 HIGH

Published 2026-08-05 · Updated 2026-08-05

AI risk analysis

Summary
The vulnerability allows for SQL injection through manipulation of the keyid argument in the logindojojs file, enabling remote attackers to exploit it for unauthorized access or data theft.
Exploitability
Exploitation is moderately difficult requiring knowledge of the specific argument and potential database structure; however, public availability of similar exploits may ease this process.
Blast radius
If exploited, the vulnerability could lead to significant data breaches or system compromise affecting users and potentially impacting organizational operations.
Prioritized remediation
Update ESAFENET CDG to the latest version immediately to patch the known vulnerability.
sql-injectionremote-exploitweb-app

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of the file /CDGServer3/ukey/usbkey;logindojojs. Such manipulation of the argument keyid leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Weaknesses

CWE-74, CWE-89

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.