ELBA5 version 5.8.0 contains a critical remote code execution vulnerability that enables unauthenticated attackers to gain SYSTEM-level command execution on affected systems. The flaw allows attackers to obtain database credentials through default connector access, decrypt the DBA password, and execute arbitrary commands via the xp_cmdshell stored procedure or by creating backdoor user accounts. This vulnerability affects ELBA5 5.8.0 and potentially other related database management products using similar authentication mechanisms. The vulnerability presents a critical threat profile with a CVSS score of 9.8, indicating high severity across all impact dimensions. The attack requires no authentication, no user interaction, and can be conducted remotely over the network with minimal complexity. Successful exploitation results in complete confidentiality, integrity, and availability compromises, granting attackers full system control. While the vulnerability is currently tracked on the active KEV/Hot List, indicating recognized exploitation interest, the EPSS score of 0.00168 suggests relatively low real-world exploitation prevalence at present. Organizations should prioritize patching ELBA5 installations immediately, as the combination of critical severity, ease of exploitation, and database credential exposure creates substantial risk even with currently limited observed exploitation activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Elba | ELBA5 | 5.8.0CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.