What is CVE-2026-51366?
CVE-2026-51366 is an SQL Injection vulnerability found in Bottinelli Informatica Vedo Suite version 1.2.5. A remote attacker can execute arbitrary code via the api_vedo/chat endpoint and the utente_chat parameter. Immediate patching of the application with the relevant security update is recommended.
Azərbaycanca: CVE-2026-51366, Bottinelli Informatica Vedo Suite 1.2.5 versiyasında aşkar edilmiş SQL Injection zəifliyidir. Uzaqdan hücumçu api_vedo/chat endpoint-i və utente_chat parametri vasitəsilə ixtiyari kod icra edə bilər. Təcili olaraq tətbiqi müvafiq təhlükəsizlik yeniləməsi ilə patch etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which version of Bottinelli Informatica Vedo Suite is affected by CVE-2026-51366?
The vulnerability affects version 1.2.5.
What endpoint and parameter must an attacker target to exploit the CVE-2026-51366 SQL Injection vulnerability?
The api_vedo/chat endpoint and the utente_chat parameter.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.