CVE-2026-14768Disclosure

LOWCVSS 5.5 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A weakness has been identified in code-projects Real State Services 1.0. This vulnerability affects unknown code of the file /builderHome.php. This manipulation of the argument loc causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-07-05); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-07-05: 2Mentions · 2026-07-06: 2PoC Mentioned / Linked · 2026-07-06: 2Patch / Workaround · 2026-07-06: 1Technical Details · 2026-07-05: 1Technical Details · 2026-07-06: 207-0507-06
Signal classification3 categories
Disclosure
250.0%
General
125.0%
PoC
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-052
Disclosure1General1
2026-07-062
Disclosure1PoC1
Full discourse4 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    #CVE-2026-14768 - #SQLi in code-projects Real State Services 1.0, via /builderHome.php?loc. Remote unauthenticated exploit public. #CVSS 7.3. No patch available. Apply #WAF or isolate. #CVEAlert #infosec #cybersecurity #developers #sysadmin #devsecops #devops https://www.valtersit.com/cve/CVE-2026-14768/

    Post summary

    CVE‑2026‑14768 is a publicly disclosed, remote unauthenticated SQL injection in Code‑Projects Real State Services 1.0 noted with a CVSS of 7.3; no patch exists, so users should isolate the system or apply a WAF.

    0000068
    974 followersView on X
  • Upwind Security MDR@UpwindMDR
    PoC

    🚨 HIGH - Remote SQL injection via loc parameter in builderHome.php (CVE-2026-14768) A SQL injection flaw has been identified in code-projects Real State Services 1.0, specifically in /builderHome.php where the loc parameter is processed unsafely. The root cause is improper input validation/unsanitized user-controlled input being concatenated into SQL queries. An unauthenticated remote attacker can exploit this over HTTP by sending crafted loc values, and a public proof-of-concept is available which lowers the barrier to exploitation. If abused, this can enable unauthorized data disclosure and modification, and can also be leveraged to disrupt service availability via heavy or destructive queries. 👉 Affected: code-projects Real State Services 1.0 | Upgrade to No fix yet — treat as suspicious

    Post summary

    The CVE-2026-14768 is a remote SQL injection vulnerability disclosed in code-projects Real State Services 1.0 with a public PoC available; no patch exists yet and there are no reports of active exploitation.

    00000110
    239 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-14768 A weakness has been identified in code-projects Real State Services 1.0. This vulnerability affects unknown code of the file /builderHome.php. This manipulation of th… https://www.cve.org/CVERecord?id=CVE-2026-14768 ----- Traducción: CVE-2026-14768 Se … http://infoflow.cloud`

    Post summary

    The post merely announces a new CVE (CVE‑2026‑14768) with minimal technical detail and no actionable information regarding exploitation, patching, or status.

    0000031
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-14768 A weakness has been identified in code-projects Real State Services 1.0. This vulnerability affects unknown code of the file /builderHome.php. This manipulation of th… https://www.cve.org/CVERecord?id=CVE-2026-14768

    Post summary

    This tweet announces a newly identified weakness in Real State Services 1.0, pointing to the /builderHome.php file, but provides no exploitation details or mitigation information.

    00000743
    57.7K followersView on X

Explore more