Cyber & AI intelligence
Wasteland.
Briefs indexed2359
Issues26
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-18765 2026-09-01

CVE-2026-18765: Critical Unauthenticated SQL Injection in Teracity E-OSB

"A CVSS 9.8 SQL injection flaw in Teracity Software Technologies Inc.'s E-OSB platform is scored to allow unauthenticated network attackers to fully compromise affected instances."

A CVSS 9.8 SQL injection flaw in Teracity Software Technologies Inc.'s E-OSB platform is scored to allow unauthenticated network attackers to fully compromise affected instances.

What Is It

CVE-2026-18765 is an improper neutralization of special elements used in an SQL command, classic SQL injection, tracked as CWE-89, in Teracity Software Technologies Inc.'s E-OSB product. User-supplied input reaches the database layer without adequate sanitization, letting an attacker inject arbitrary SQL.

The vulnerability was published on 2026-09-01 and reported by USOM (Turkey's National Cyber Incident Response Center), which is the assigning source for the record. NVD currently lists the entry with a vulnerability status of "Received."

Why It Matters

The CVSS v3.1 base score is 9.8 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Every factor works in the attacker's favor:

Impact is High across confidentiality, integrity, and availability (exploitability subscore 3.9, impact subscore 5.9). Successful exploitation would likely give full read and write access to backing database contents, though the CVSS metrics alone do not confirm the practical extent.

What's Vulnerable

No CPE entries are currently published for this CVE, so automated inventory matching against the NVD feed will not flag affected assets; identification must be done by vendor and version.

Patch Status

Version V02.26.07.08.01 and later are not affected. Organizations running E-OSB should upgrade to V02.26.07.08.01 or newer. Until then, restrict network exposure of E-OSB instances to trusted sources.

Neither of the sources cited below speaks to exploitation status, and neither is authoritative on CISA KEV listings. Defenders should check the CISA Known Exploited Vulnerabilities catalog directly for the current KEV status of CVE-2026-18765 and any associated federal remediation deadline, rather than inferring either from the NVD record. Whatever that check returns, an unauthenticated, network-reachable 9.8 warrants prompt patching on its technical severity alone.

Sources