What is CVE-2026-6881?
A SQL Injection vulnerability exists in the Giving Reports functionality of Ellucian Advance Web and Legacy Advance, allowing an authenticated attacker to extract sensitive database information via a crafted SQL query in the class credit field. All versions are affected, requiring immediate patching with vendor-provided updates.
Azərbaycanca: Bu SQL Injection zəifliyi Ellucian Advance Web və Legacy Advance sistemlərinin Giving Reports funksionallığında aşkarlanıb. Doğrulanmış hücumçuya class credit sahəsi vasitəsilə xüsusi SQL sorğuları göndərərək verilənlər bazasından həssas məlumatları əldə etməyə imkan verir. Bütün versiyalar təsirlənmiş sayıldığı üçün dərhal vendor tərəfindən təqdim edilən yeniləmələr tətbiq olunmalıdır.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Does exploiting CVE-2026-6881 in Ellucian Advance systems require the attacker to be authenticated?
Yes, this SQL Injection vulnerability can only be exploited by an authenticated attacker.
In which functionality of Ellucian Advance does CVE-2026-6881 exist?
The vulnerability exists in the Giving Reports functionality, specifically exploited via the 'class credit' field.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.