ZeroHour

CVE-2026-40018

SQL Injection in Open-Xchange Product (CVE-2026-40018)

CVSS 3.1
7.4 high
EPSS
<1%p19
Published
()
Modified
AI analysis

CVE-2026-40018 is a SQL injection vulnerability (CWE-89) in a product maintained by Open-Xchange, whose security team is the assigned CNA and the authoritative source for the affected product and version details, which are not included in the available data. Based on the CVSS 3.1 vector (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N), the flaw is remotely exploitable over a network with no authentication and no user interaction required, but the high attack complexity means successful exploitation depends on conditions largely outside the attacker's control. A successful attack can give the attacker unauthorized read access to data and the ability to modify it (C:H/I:H), without disrupting availability (A:N). All deployments of the affected Open-Xchange product should be treated as potentially exposed pending publication of the affected version range. As of now there is no known public exploit or PoC, the flaw is not in CISA's KEV, and EPSS estimates only about a 0.3% chance of exploitation in the next 30 days.

What to do: No fixed version numbers are provided in the available data; monitor the Open-Xchange security advisory for CVE-2026-40018 and apply the vendor patch promptly when it is published. In the interim, inventory your environment for Open-Xchange products, limit network and database access to them, and consider WAF rules that filter SQL injection patterns. Given the high attack complexity, absence of known exploits, and low EPSS (0.3%), this is not an emergency, but schedule patching as soon as advisory details become available.

Affected
Open-Xchange
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

None None None No publicly available exploits are known.

Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.