CVE-2026-89180
nicheUnauthenticated SQL Injection in Thinking Software EFence
EFence, a product developed by Taiwan-based Thinking Software Technology, contains a SQL injection flaw (CWE-89) that allows unauthenticated remote attackers to submit arbitrary SQL commands, presumably through unvalidated input accepted by the product's network-facing interface. Because no authentication is required and the attack complexity is low (CVSS 4.0 base score 8.7, high), an attacker who can reach the vulnerable service can extract the contents of the backend database. The impact is limited to confidentiality — there is no indication in the advisory of code execution or integrity/availability effects. Organizations running EFence, particularly any instance reachable from untrusted networks, are affected. There is no known public proof of concept and no evidence of exploitation in the wild; the CVE is not on the CISA Known Exploited Vulnerabilities catalog.
What to do: Contact Thinking Software Technology or check the TWCERT-CC advisory for a patched release and upgrade as soon as fixed versions are identified, since the source advisory lists no version ranges. In the interim, restrict network access to the EFence service (management interface allow-listing or VPN-only exposure) so unauthenticated remote attackers cannot reach the vulnerable endpoints. Review database and application logs for anomalous SQL queries or unexpected data reads that could indicate probing or attempted exploitation.
| Thinking Software Technology EFence | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
EFence developed by Thinking Software Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.
- Weakness
- CWE-89
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.