← Back to search

CVE-2026-72507

9 CRITICALpublic exploit available

Published 2026-09-29 · Updated 2026-09-29

AI risk analysis

Summary
The flaw is a time-based blind SQL injection vulnerability in the 'reportType' parameter, allowing attackers to inject malicious SQL queries and potentially gain unauthorized access or manipulate data. This matters because it can lead to severe data breaches and system compromise.
Exploitability
Exploitation requires knowledge of the specific SQL injection technique and access to the 'reportType' parameter. Precondition is that the feature is enabled and the application is not properly sanitized.
Blast radius
If exploited, this vulnerability could lead to data theft, unauthorized data manipulation, and potential system compromise affecting users and operations.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the affected feature or restrict access to the 'reportType' parameter until a patch is available.
sql-injectionblind-sqlwebdata-breach

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The "reportType" parameter in the product summary report feature within the balancing reports section is susceptible to a time-based blind SQL injection vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H

Weaknesses

CWE-89

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.