CVE-2026-2247Disclosure

LOWCVSS 8.3 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SQL injection vulnerability (SQLi) in Clicldeu SaaS, specifically in the generation of reports, which occurs when a previously authenticated remote attacker executes a malicious payload in the URL generated after downloading the student's report card in the ‘Day-to-day’ section from the mobile application. In the URL of the generated PDF, the session token used does not expire, so it remains valid for days after its generation, and unusual characters can be entered after the ‘id_alu’ parameter, resulting in two types of SQLi: boolean-based blind and time-based blind. Exploiting this vulnerability could allow an attacker to access confidential information in the database.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-02-17: 4Patch / Workaround · 2026-02-17: 1Technical Details · 2026-02-17: 402-17
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • INCIBE-CERT@incibe_cert
    Disclosure

    ⚠️#INCIBEaviso | Inyección SQL en la plataforma SaaS de #Clickedu #CVE CVE-2026-2247 https://www.incibe.es/incibe-cert/alerta-temprana/avisos/inyeccion-sql-en-la-plataforma-saas-de-clickedu #AvisosDeSeguridad #TI #CNA #0day https://t.co/213ps2WiK3

    Post summary

    A new SQL injection vulnerability (CVE-2026-2247) has been disclosed for the Clickedu SaaS platform, with an alert issued by INCIBE, but no evidence of exploitation or patch details is provided.

    02050483
    42.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2247 SQL injection vulnerability (SQLi) in Clicldeu SaaS, specifically in the generation of reports, which occurs when a previously authenticated remote attacker executes a … https://www.cve.org/CVERecord?id=CVE-2026-2247

    Post summary

    The text announces CVE-2026-2247, a SQL injection flaw affecting report generation in Clicldeu SaaS for authenticated remote attackers.

    00011286
    56.4K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 HIGH-severity SQL injection in Clickedu SaaS lets authenticated users steal sensitive student data via report card URLs. All versions affected — patch ASAP! 🛡️ https://radar.offseq.com/threat/cve-2026-2247-cwe-89-improper-neutralization-of-sp-b8f5f03e #OffSeq #SQLi #EduTech https://t.co/c4kfze599M

    Post summary

    The tweet alerts to a high‑severity SQL injection in Clickedu SaaS affecting all versions and urges immediate patching, without providing PoC or exploit details.

    0000044
    265 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2247 SQL Injection in Clicldeu SaaS Mobile App Enabling Unauthorized Database Access https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2247

    Post summary

    CVE-2026-2247 is an SQL injection vulnerability in the Clicldeu SaaS mobile application that could allow unauthorized database access, as noted in a brief disclosure on Vulmon.

    0000048
    4.0K followersView on X

Explore more