CVE-2026-8025

CRITICAL

SQLi in MOSK Informatics' CBS Platform

Title source: cna
STIX 2.1

Description

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information Technologies Ltd. CBS Platform allows SQL Injection. This issue affects CBS Platform: through 09062026.  NOTE: The vendor was contacted and it was learned that the product is not supported.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0027
EPSS Percentile 19.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
MOSK Information Technologies Ltd./CBS Platform < 09062026
Published Jun 09, 2026
Tracked Since Jun 09, 2026