SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-16019 2026-08-19

CVE-2026-16019: Critical SQL Injection in FAYDAM Datalogger

"A critical, unauthenticated SQL injection flaw (CVSS 9.8) affects FAYDAM Datalogger versions 2.7.1 through 2.7.x, allowing remote attackers to compromise data confidentiality, integrity, and availability."

A critical, unauthenticated SQL injection flaw (CVSS 9.8) affects FAYDAM Datalogger versions 2.7.1 through 2.7.x, allowing remote attackers to compromise data confidentiality, integrity, and availability.

What Is It

CVE-2026-16019 is an improper neutralization of special elements used in an SQL command, classic SQL injection, tracked as CWE-89, in Faydam Innovation Inc.'s FAYDAM Datalogger product. The vulnerability was published on 2026-08-19 and reported through USOM, Turkey's national cyber incident response center, which acts as the CNA for this record and carries the corresponding notice on Turkey's national cyber security portal.

The CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, producing a base score of 9.8 (CRITICAL). Every exploitability dimension is worst-case: the attack is reachable over the network, requires low complexity, needs no privileges, and needs no user interaction. Exploitability sub-score is the maximum 3.9; impact sub-score is 5.9.

Why It Matters

An unauthenticated, network-reachable SQL injection against a datalogger platform means an attacker who can reach the interface can potentially read, modify, and destroy the logged data; the confidentiality, integrity, and availability impacts are all rated HIGH. Dataloggers typically sit in industrial and monitoring environments where the recorded data drives operational decisions, so integrity loss is as consequential as data theft.

No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation at this time. The absence of a KEV listing is not evidence that exploitation is not occurring; only that it has not been catalogued in the material reviewed here.

What's Vulnerable

No CPE entries were published in the NVD record at the time of writing, which may limit automated asset-inventory matching.

Patch Status

The version range in the advisory indicates that 2.8.0 is the fixed release. Operators running any build in the 2.7.1–2.7.x range should upgrade to 2.8.0 or later. No workaround or mitigation was published in the supplied source material. The NVD record is in Received status, meaning NVD enrichment and analysis were still pending as of 2026-08-19.

Sources