Successful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to
execute arbitrary commands via a specific interface,
potentially enabling the attacker to access, modify, or delete sensitive
information within the database.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Users and administrators of affected product versions are advised to update to the latest versions immediately. For SaaS Composer, IoTSuite Growth Linux docker, IoT Edge Windows, and ECOWatch please contact Advantech  here  https://wise-iot.advantech.com/en-tw/marketplace/help/technical-support for the official release of the fixed version. For IoTSuite Starter Linux docker, please refer to the update guide  here https://portal-kbinsight-wiseiot-ensaas.practice.cloud.advantech.com/kb/library/detail/oPN5exOVNQq . As the update involves a reinstallation process, please refer to the reinstallation guide here https://portal-kbinsight-wiseiot-ensaas.practice.cloud.advantech.com/kb/library/detail/JqNWAMGz1JQ . For IoT Edge Linux docker, please refer to the update guide  here https://portal-kbinsight-wiseiot-ensaas.practice.cloud.advantech.com/kb/library/detail/oPN5exOVNQq . As the update involves a reinstallation process, please refer to the reinstallation guide here https://portal-kbinsight-wiseiot-ensaas.practice.cloud.advantech.com/kb/library/detail/G0yWBn2mp2q . For WebAccess/SCADA and WebAccess SaaS-Composer, please refer to the update guide here https://www.advantech.com/en/support/details/installation .


Workaround

No workaround given by the vendor.

History

Wed, 13 May 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89

Wed, 13 May 2026 03:30:00 +0000

Type Values Removed Values Added
Description Successful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to execute arbitrary commands via a specific interface, potentially enabling the attacker to access, modify, or delete sensitive information within the database.
Title SQL Injection Vulnerability
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CSA

Published:

Updated: 2026-05-13T03:16:24.701Z

Reserved: 2026-04-23T02:58:12.750Z

Link: CVE-2026-6888

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-13T05:00:14Z

Weaknesses