SYS::ONLINE
Wasteland.
Briefs1674
Issues21
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-7486 2026-06-09

CVE-2026-7486: Critical SQL Injection in Netcad E-İmar

"A critical SQL injection vulnerability (CVSS 9.8) in Netcad Software's E-İmar permits unauthenticated, network-based attackers to inject arbitrary SQL commands against affected deployments."

A critical SQL injection vulnerability (CVSS 9.8) in Netcad Software's E-İmar permits unauthenticated, network-based attackers to inject arbitrary SQL commands against affected deployments.

What Is It

CVE-2026-7486 is an improper neutralization of special elements used in an SQL command (SQL injection, CWE-89) vulnerability in Netcad Software Inc. E-İmar. It carries a CVSS 3.1 base score of 9.8 (CRITICAL) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning it is remotely exploitable over the network, requires low attack complexity, and needs no privileges or user interaction.

Why It Matters

The flaw scores HIGH across confidentiality, integrity, and availability impacts. Because exploitation requires no authentication and no user interaction, an attacker reaching an affected E-İmar instance over the network can potentially read, alter, or destroy database contents. The maximum exploitability sub-score (3.9) reflects how readily this can be triggered.

What's Vulnerable

The vulnerability affects Netcad Software Inc. E-İmar from version 2.10.1.0 up to (but not including) 3.0.2. No specific affected CPE configurations were enumerated in the NVD record.

Patch Status

The advisory indicates the issue is resolved in E-İmar version 3.0.2; versions from 2.10.1.0 before 3.0.2 remain affected. Organizations running affected versions should upgrade to 3.0.2 or later. This CVE was published on 2026-06-09 and currently carries an NVD status of "Deferred." No CISA KEV entry confirming active exploitation was supplied with this record.

Sources