CVE-2026-32969

7.5

MB connect line, Helmholz · mbCONNECT24, mymbCONNECT24, myREX24V2, myREX24V2.virtual

An unauthenticated blind SQL injection vulnerability in the userinfo endpoint allows remote attackers to compromise system confidentiality through improper neutralization of SQL commands.

Executive summary

Multiple industrial connectivity products from MB connect line and Helmholz are vulnerable to unauthenticated SQL injection, posing a critical risk to data confidentiality.

Vulnerability

This is a blind SQL injection vulnerability (CWE-89) affecting the userinfo endpoint. The vulnerability is exploitable by unauthenticated remote attackers who can inject malicious SQL commands to extract data from the backend database.

Business impact

The exploitation of this vulnerability allows for the unauthorized extraction of sensitive data, leading to a total loss of confidentiality. With a CVSS score of 7.5, this high-severity flaw in industrial connectivity infrastructure could lead to significant operational disruption and the exposure of proprietary or sensitive user information.

Remediation

Immediate Action: Consult the official VDE advisories (VDE-2026-024 and VDE-2026-025) to determine if a patched version beyond 2.19.3 is available and apply it immediately.

Proactive Monitoring: Implement strict database query logging and monitor for unusual query patterns or spikes in traffic to the userinfo endpoint.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common SQL injection patterns targeted at the affected endpoints.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for total loss of confidentiality in these critical industrial connectivity products, administrators must prioritize this vulnerability. If a vendor patch is not yet available, restrict network access to the affected devices to trusted sources only and monitor logs for signs of unauthorized database interaction until a permanent fix can be applied.

Sources

Originally found and disclosed by Moritz Abrell, Christian Zäske from SySS GmbH, per the CVE Program record.