CVE-2026-72507
9 CRITICALpublic exploit availablePublished 2026-09-29 · Updated 2026-09-29
AI risk analysis
- Summary
- The flaw is a time-based blind SQL injection vulnerability in the 'reportType' parameter, allowing attackers to inject malicious SQL queries and potentially gain unauthorized access or manipulate data. This matters because it can lead to severe data breaches and system compromise.
- Exploitability
- Exploitation requires knowledge of the specific SQL injection technique and access to the 'reportType' parameter. Precondition is that the feature is enabled and the application is not properly sanitized.
- Blast radius
- If exploited, this vulnerability could lead to data theft, unauthorized data manipulation, and potential system compromise affecting users and operations.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Disable the affected feature or restrict access to the 'reportType' parameter until a patch is available.
sql-injectionblind-sqlwebdata-breach
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
The "reportType" parameter in the product summary report feature within the balancing reports section is susceptible to a time-based blind SQL injection vulnerability.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H
Weaknesses
CWE-89
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-68068PoC
- HIGHCVE-2026-78309
- CRITICALCVE-2026-15721
- HIGHCVE-2022-4997
- CRITICALCVE-2023-54399
- CRITICALCVE-2023-54400PoC
- CRITICALCVE-2025-63564
- CRITICALCVE-2026-12718
Related by shared AI tags and CWE weakness class. Browse the full archive.