CVE-2026-24494Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SQL Injection vulnerability in the /api/integrations/getintegrations endpoint of Order Up Online Ordering System 1.0 allows an unauthenticated attacker to access sensitive backend database data via a crafted store_id parameter in a POST request.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-02-23); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-23: 1Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Mentions · 2026-03-03: 1Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 102-2302-2702-2803-03
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-231
Disclosure1
2026-02-271
Disclosure1
2026-02-281
Disclosure1
2026-03-031
General1
Full discourse4 posts
  • AgniOps@AgniOpsIn
    General

    🚨 CVE-2026-24494 explained A real-world vulnerability breakdown—impact, attack surface, and what defenders must watch for. Understanding CVEs isn’t optional if you want real security. 🔗 https://www.agniops.in/post/cve-2026-24494 #CVE #CyberSecurity #VulnerabilityResearch #AgniOps

    Post summary

    The tweet announces a post that explains CVE-2026-24494, but it does not provide any specific technical, exploit, or mitigation details.

    0000042
    2 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-24494 (CVSS:9.8, CRITICAL) is Awaiting Analysis. SQL Injection vulnerability in the /api/integrations/getintegrations endpoint of Order Up Online Ordering System 1.0 all..https://nvd.nist.gov/vuln/detail/CVE-2026-24494 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-24494 is an SQL Injection vulnerability in the Order Up Online Ordering System 1.0, classified as critical with CVSS 9.8, currently awaiting analysis.

    0000025
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-24494 (CVSS:9.8, CRITICAL) is Awaiting Analysis. SQL Injection vulnerability in the /api/integrations/getintegrations endpoint of Order Up Online Ordering System 1.0 all..https://nvd.nist.gov/vuln/detail/CVE-2026-24494 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces the discovery of CVE-2026-24494, a critical SQL injection vulnerability in Order Up Online Ordering System 1.0, without any evidence of exploitation, PoC, or remediation.

    0000018
    173 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-24494 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-24494 #CVE-2026-24494 #CVE #Critical #CyberSecurity #InfoSec https://t.co/Kss01GbGfx

    Post summary

    A new critical CVE (CVE-2026-24494) has been announced with a severity score of 9.8, affecting multiple unspecified products, but no further technical details or mitigation information are provided.

    0000051
    57 followersView on X

Explore more