CVE-2026-18198
—Blind SQL Injection in TAC Information Services GOLDENHORN ONEIT
GOLDENHORN ONEIT, a product of TAC Information Services (TAC Information Services Internal and External Trade Inc.), does not properly neutralize special elements used in SQL commands, allowing blind SQL injection (CWE-89). An attacker sends crafted input that reaches the application's SQL queries; because the injection is blind, data is extracted indirectly by inferring behavior from the application's responses rather than direct error or output, and the CVSS vector indicates a valid low-privileged account and network access are required. Successful exploitation carries high impact to confidentiality, integrity, and availability (CVSS 3.1: 8.8), meaning an attacker could potentially read, modify, or disrupt the underlying database. All releases of GOLDENHORN ONEIT prior to the 'Göbeklitepe' version are affected. There are currently no known in-the-wild exploits, no public proof-of-concept, the EPSS score is about 0.2% over the next 30 days, and the flaw is not in CISA's Known Exploited Vulnerabilities catalog.
What to do: Upgrade GOLDENHORN ONEIT to the Göbeklitepe release or later, which remediates the SQL injection flaw. Until patched, restrict network access to the application to trusted users, review user accounts for unexpected access, and check application and database logs for signs of SQL injection probing or anomalous query timing.
| TAC Information Services Internal and External Trade Inc. GOLDENHORN ONEIT | all versions before Göbeklitepe |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TAC Information Services Internal and External Trade Inc. GOLDENHORN ONEIT allows Blind SQL Injection. This issue affects GOLDENHORN ONEIT: before Göbeklitepe.
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.