ZeroHour

CVE-2026-7188

Unauthenticated SQL Injection in Armiya Access Control System

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-7188 is a critical SQL injection flaw (CWE-89) in Armiya Information Technologies' Access Control System, caused by improper neutralization of special elements in SQL commands. Because the flaw is exploitable over the network with no privileges or user interaction required (per the CVSS 3.1 vector), an unauthenticated attacker can send crafted input to reach the backend database. Successful exploitation could allow reading or modifying sensitive stored data, such as access credentials, cardholder records, or entry logs, and potentially bypassing authentication in the access control workflow. Any deployment running Access Control System versions prior to Version 2 (Versiyon 2) is affected. There are currently no known public proofs of concept, no reports of in-the-wild exploitation, and the vulnerability is not listed in CISA's KEV catalog.

What to do: Upgrade Access Control System to Version 2 (Versiyon 2) or later. Until patched, restrict network access to the system (especially avoid internet exposure), and review database and application logs for signs of unusual or injected SQL queries.

Affected
Armiya Information Technologies Ltd. Co. Access Control Systemall versions before Version 2 (Versiyon 2)
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows SQL Injection. This issue affects Access Control System: before Versiyon 2.

Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.