CVE-2026-1198Disclosure

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SIMPLE.ERP is vulnerable to the SQL Injection in search functionality in "Obroty na kontach" window. Lack of input validation allows an authenticated attacker to prepare a malicious query to the database that will be executed. This issue was fixed in [email protected]_u06.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-26); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-26: 2Mentions · 2026-02-27: 1Patch / Workaround · 2026-02-27: 1Technical Details · 2026-02-26: 2Technical Details · 2026-02-27: 102-2602-27
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-262
Disclosure2
2026-02-271
Disclosure1
Full discourse3 posts
  • Misbar | مسبار@MisbarSec
    Disclosure

    🚨 اكتشاف ثغرة في برنامج Simple.ERP تم اكتشاف ثغرة أمنية حرجة CVE-2026-1198 في برنامج Simple.ERP من شركة Simple SA. هذه الثغرة تؤثر على جميع الإصدارات قبل 6.30@A04.4_u06. استغلالها قد يمنح المهاجم وصولاً غير مصرح به. 💡 خطوات الحماية: - تحديث برنامج Simple.ERP إلى أحدث إصدار متوفر. - مراجعة سجلات النظام للكشف عن أي نشاط مشبوه. - تطبيق ضوابط وصول صارمة للمستخدمين. 🔗 https://cert.pl/en/posts/2026/02/CVE-2026-1198/ #الأمن_السيبراني #ثغرات #SimpleERP

    Post summary

    A critical CVE-2026-1198 vulnerability in Simple.ERP affecting all pre‑6.30 versions has been disclosed, with no PoC or active exploitation mentioned; users are urged to update and apply security controls.

    0002022
    51 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-1198 - SQL Injection in SIMPLE.ERP Intel Report: https://ift.tt/UFlIo2B

    Post summary

    An intel report alerts about CVE-2026-1198, a SQL injection vulnerability in SIMPLE.ERP, with no mention of PoC, exploit, patch, or active exploitation.

    000005
    338 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1198 SIMPLE.ERP is vulnerable to the SQL Injection in search functionality in "Obroty na kontach" window. Lack of input validation allows an authenticated attacker to prepar… https://www.cve.org/CVERecord?id=CVE-2026-1198

    Post summary

    The post announces that SIMPLE.ERP has a SQL injection vulnerability (CVE-2026-1198) in the 'Obroty na kontach' search window, requiring authentication, with no mention of PoC, exploit, or patch.

    0000082
    56.6K followersView on X

Explore more