CVE-2026-33616 details an unauthenticated blind SQL Injection vulnerability impacting MB connect line mbCONNECT24 products, specifically within the mb24api endpoint. This high-severity flaw, rated 7.5 CVSS, allows a remote attacker to exploit improper input neutralization without authentication or user interaction. Successful exploitation can lead to a total loss of confidentiality. Currently, there is no evidence of active exploitation, and public exploit modules or proof-of-concept code are not available. While not listed on CISA's Known Exploited Vulnerabilities catalog, the vulnerability has garnered some discussion within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.19.4CPE matchmatch criteria | cpe:2.3:a:mbconnectline:mbconnect24:*:*:*:*:*:*:*:* | ||
<= 2.19.4CPE matchmatch criteria | cpe:2.3:a:mbconnectline:mymbconnect24:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.