← Back to search

CVE-2026-68068

9 CRITICALpublic exploit available

Published 2026-09-29 · Updated 2026-09-29

AI risk analysis

Summary
This vulnerability allows an attacker to inject time-based SQL queries, potentially leading to data theft or system compromise.
Exploitability
Exploitation requires knowledge of the exact SQL query structure and timing, making it moderately difficult. Precondition is access to the 'screenID' parameter in the manual transactions section.
Blast radius
If exploited, attackers could gain unauthorized access to sensitive data within the electronic transaction queue viewer.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the affected feature until a patch is available.
sql-injectionblind-sqlweb

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The "screenID" parameter in the electronic transaction queue viewer feature within the manual transactions section is susceptible to a time-based blind SQL injection vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H

Weaknesses

CWE-89

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.