ZeroHour

CVE-2026-5956

niche

SQL Injection in Ankara Hosting Site Management Panel

CVSS 3.1
8.8 high
EPSS
<1%p15
Published
()
Modified
AI analysis

CVE-2026-5956 is an SQL injection flaw (CWE-89) in the Ankara Hosting Site Management Panel, caused by improper neutralization of special elements used in SQL commands. It is triggered over the network by a user with a low-privileged (authenticated) account, who can inject crafted SQL into unsanitized panel input without any user interaction. Successful exploitation could allow the attacker to read, modify, or potentially delete data in the backend database, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8). All versions of Site Management Panel up to and including the 15062026 build are affected, which plausibly covers deployments used by Ankara Hosting's hosting customers. There is currently no public proof-of-concept and no known exploitation in the wild; the EPSS score of 0.2% (15th percentile) and the absence from CISA KEV suggest low near-term exploitation risk.

What to do: Upgrade Site Management Panel to a release newer than 15062026 as soon as Ankara Hosting publishes a fix, verifying the patched version with the vendor or via the USOM advisory (no fixed version is specified in current data). Until patched, restrict panel access to trusted users, enforce strong credentials and least privilege for panel accounts since exploitation requires an authenticated session, and consider WAF rules that filter SQL metacharacters. Review panel and database logs for anomalous or malformed queries that could indicate attempted injection.

Affected
Ankara Hosting Site Management Panelall versions through and including 15062026
Estimated exposure
nicheunknown - plausibly hundreds to low thousands of panel deployments — No public installation counts, scan data, or market-share figures exist for this proprietary panel from a single Turkish hosting provider, so the plausible footprint is limited to that provider's hosting customers and their managed sites.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Ankara Hosting Site Management Panel allows SQL Injection. This issue affects Site Management Panel: through 15062026.

Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.