A critical SQL injection vulnerability (CVSS 9.8) in Netcad Software's E-İmar permits unauthenticated, network-based attackers to inject arbitrary SQL commands against affected deployments.
What Is It
CVE-2026-7486 is an improper neutralization of special elements used in an SQL command (SQL injection, CWE-89) vulnerability in Netcad Software Inc. E-İmar. It carries a CVSS 3.1 base score of 9.8 (CRITICAL) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning it is remotely exploitable over the network, requires low attack complexity, and needs no privileges or user interaction.
Why It Matters
The flaw scores HIGH across confidentiality, integrity, and availability impacts. Because exploitation requires no authentication and no user interaction, an attacker reaching an affected E-İmar instance over the network can potentially read, alter, or destroy database contents. The maximum exploitability sub-score (3.9) reflects how readily this can be triggered.
What's Vulnerable
The vulnerability affects Netcad Software Inc. E-İmar from version 2.10.1.0 up to (but not including) 3.0.2. No specific affected CPE configurations were enumerated in the NVD record.
Patch Status
The advisory indicates the issue is resolved in E-İmar version 3.0.2; versions from 2.10.1.0 before 3.0.2 remain affected. Organizations running affected versions should upgrade to 3.0.2 or later. This CVE was published on 2026-06-09 and currently carries an NVD status of "Deferred." No CISA KEV entry confirming active exploitation was supplied with this record.