CVE-2026-18630
TMT Machine Industry and Trade Ltd. Co. · Talassoft Industrial Management Software
Talassoft Industrial Management Software is vulnerable to SQL injection due to improper neutralization of special elements in SQL commands, potentially allowing unauthorized database interactions.
Executive summary
An SQL injection vulnerability in Talassoft Industrial Management Software versions 4 through 15 poses a high risk of unauthorized data access and manipulation.
Vulnerability
This is an SQL injection flaw (CWE-89) where an authenticated user with low privileges can inject malicious SQL commands into the application, potentially leading to unauthorized data retrieval or modification. The vulnerability exists because the software fails to properly sanitize user supplied input before processing database queries.
Business impact
The exploitation of this vulnerability could lead to a total compromise of the database contents, including sensitive industrial or management data. Given the CVSS score of 8.8, this flaw represents a significant risk to data integrity and confidentiality, potentially resulting in severe operational disruption or regulatory non-compliance.
Remediation
Immediate Action: Contact TMT Machine Industry and Trade Ltd. Co. support to obtain and deploy the necessary security updates to upgrade to version 16 or later.
Proactive Monitoring: Monitor database query logs for unusual syntax, unexpected error messages, or high volumes of queries originating from standard user accounts.
Compensating Controls: Deploy a Web Application Firewall (WAF) with SQL injection protection rules to inspect and block malicious traffic targeting the application endpoints.
Exploitation status
Public Exploit Available: No (exploit_available: false).
Analyst recommendation
This vulnerability presents a critical threat to the security of your industrial management environment. Administrators should verify their current version of Talassoft and prioritize the transition to version 16 or newer immediately to eliminate the risk of SQL injection, as database-level compromises are often difficult to detect and remediate after the fact.
More TMT Machine Industry and Trade Ltd. Co. CVEs
Sources
Originally found and disclosed by Efe Özel, with Cemil Sefa Özcan (analyst), FORDEFENCE (sponsor), per the CVE Program record.