CVE-2026-18765
nicheUnauthenticated SQL Injection in Teracity E-OSB
CVE-2026-18765 is a SQL injection flaw (CWE-89) in Teracity Software Technologies' E-OSB platform, where user-supplied input is not properly neutralized before being used in an SQL command, allowing attackers to inject arbitrary SQL. The CVSS vector (network attack vector, low complexity, no privileges or user interaction required) indicates an unauthenticated remote attacker can trigger the flaw directly through the application. Successful exploitation could give the attacker access to the underlying database, enabling reading, modification, or deletion of data, with potential for further compromise depending on database contents and privileges. Affected organizations are those running E-OSB in any version before V02.26.07.08.01. Exploitation has not been observed: there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at roughly 0.3%.
What to do: Upgrade E-OSB to V02.26.07.08.01 or later. If immediate upgrade is not possible, limit internet exposure of the E-OSB application and review web/database logs for signs of SQL injection attempts. Since exposure numbers are not publicly documented, inventory your environment to confirm whether this product is deployed anywhere in your estate.
| Teracity Software Technologies Inc. E-OSB | all versions before V02.26.07.08.01 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection. This issue affects E-OSB: before V02.26.07.08.01.
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.