CVE-2026-2620

HIGH

Huace Monitoring 2.2 - SQL Injection

Title source: llm
STIX 2.1

Description

A weakness has been identified in Huace Monitoring and Early Warning System 2.2. Affected by this issue is some unknown functionality of the file /Web/SysManage/ProjectRole.aspx. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.346271
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.346271
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.751808

Scores

CVSS v3 7.3
EPSS 0.0025
EPSS Percentile 16.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-74 CWE-89
Status published
Products (1)
Huace/Monitoring and Early Warning System 2.2
Published Feb 17, 2026
Tracked Since Feb 18, 2026