What is CVE-2026-18859?
A SQL injection vulnerability in ESAFENET CDG up to version 20260615 allows remote attackers to manipulate the `keyid` argument in the `/CDGServer3/ukey/usbkey;logindojojs` file, potentially leading to unauthorized database access. Immediate patching is recommended as a public exploit is available.
Azərbaycanca: ESAFENET CDG 20260615-ə qədər versiyalarında `/CDGServer3/ukey/usbkey;logindojojs` faylında `keyid` parametrinin düzgün yoxlanılmaması SQL injection zəifliyinə səbəb olur. Bu, uzaqdan hücumçuya verilənlər bazasına icazəsiz sorğular göndərməyə imkan verir. Mütəxəssislər dərhal proqram təminatını yeniləməyi tövsiyə edir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of ESAFENET CDG are affected by this vulnerability?
The CVE-2026-18859 vulnerability affects ESAFENET CDG up to version 20260615.
What can an attacker achieve by exploiting this SQL injection vulnerability?
An attacker can send unauthorized SQL queries to the database by exploiting the `keyid` parameter in the `/CDGServer3/ukey/usbkey;logindojojs` file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.