← Back to search

CVE-2026-68954

9 CRITICALpublic exploit available

Published 2026-09-29 · Updated 2026-09-29

AI risk analysis

Summary
The vulnerability allows an attacker to inject time-based SQL queries, potentially leading to data theft or system compromise.
Exploitability
Exploitation requires crafting a specific pattern input, which is moderately difficult. The attacker must be able to observe the application's response times to infer the SQL injection payload.
Blast radius
If exploited, the attacker could gain access to sensitive data or execute arbitrary SQL commands, impacting the integrity and confidentiality of the application's data.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the search function on the home page until a patch is available, or upgrade to the latest version of the TMS application.
sql-injectionwebblindtime-based

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The "pattern" parameter used in search function in the home page of the TMS application is vulnerable to time-based blind SQL injection vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H

Weaknesses

CWE-89

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.