ZeroHour

CVE-2026-89180

niche

Unauthenticated SQL Injection in Thinking Software EFence

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

EFence, a product developed by Taiwan-based Thinking Software Technology, contains a SQL injection flaw (CWE-89) that allows unauthenticated remote attackers to submit arbitrary SQL commands, presumably through unvalidated input accepted by the product's network-facing interface. Because no authentication is required and the attack complexity is low (CVSS 4.0 base score 8.7, high), an attacker who can reach the vulnerable service can extract the contents of the backend database. The impact is limited to confidentiality — there is no indication in the advisory of code execution or integrity/availability effects. Organizations running EFence, particularly any instance reachable from untrusted networks, are affected. There is no known public proof of concept and no evidence of exploitation in the wild; the CVE is not on the CISA Known Exploited Vulnerabilities catalog.

What to do: Contact Thinking Software Technology or check the TWCERT-CC advisory for a patched release and upgrade as soon as fixed versions are identified, since the source advisory lists no version ranges. In the interim, restrict network access to the EFence service (management interface allow-listing or VPN-only exposure) so unauthenticated remote attackers cannot reach the vulnerable endpoints. Review database and application logs for anomalous SQL queries or unexpected data reads that could indicate probing or attempted exploitation.

Affected
Thinking Software Technology EFence
Estimated exposure
nicheLikely hundreds to low thousands of deployments (order of magnitude only; no public count exists) — No public install counts, market share figures, or internet-wide scan data are available; the estimate is based on deployment patterns for a commercial enterprise product from a small regional (Taiwanese) vendor, clearly a rough inference…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

EFence developed by Thinking Software Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

Weakness
CWE-89
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.