A critical, unauthenticated SQL injection flaw affects all versions of the MOSK Information Technologies CBS Platform, a product the vendor has confirmed is no longer supported.
What Is It
CVE-2026-8025 is an SQL injection vulnerability (CWE-89) in the MOSK Information Technologies Ltd. CBS Platform. The flaw stems from improper neutralization of special elements used in an SQL command, allowing an attacker to inject malicious SQL. It carries a CVSS 3.1 base score of 9.8 (CRITICAL), with a vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning it is exploitable remotely over the network, requires low attack complexity, and needs neither privileges nor user interaction.
Why It Matters
The combination of network-based access, no authentication, and high impact across confidentiality, integrity, and availability makes this an attractive target. A successful SQL injection can expose, alter, or destroy backend database contents. Critically, the vendor was contacted and confirmed the CBS Platform is not supported, so no official fix is expected. The CVE is tagged unsupported-when-assigned, underscoring that affected organizations cannot rely on a vendor patch.
What's Vulnerable
The MOSK Information Technologies Ltd. CBS Platform is affected through version 09062026 (i.e., all builds up to and including that dated release). The NVD record lists no specific CPE entries.
Patch Status
No patch is available. The vendor has indicated the product is end-of-life and unsupported, so a security update is not anticipated. Organizations running the CBS Platform should treat this as a permanent exposure: isolate or decommission affected instances, restrict network access to the application, and consider migrating to a supported alternative. This CVE was published and coordinated through Turkey's national cybersecurity authority (USOM). The supplied source material does not include a CISA KEV entry, so active exploitation is not confirmed here.
Sources
- NVD, CVE-2026-8025: https://nvd.nist.gov/vuln/detail/CVE-2026-8025
- USOM / Siber Güvenlik Bildirimleri (TR-26-0344): https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0344