
CVE-2026-33616 An unauthenticated remote attacker can exploit an unauthenticated blind SQL Injection vulnerability in the mb24api endpoint due to improper neutralization of special … https://www.cve.org/CVERecord?id=CVE-2026-33616
Post summary
The text announces CVE-2026-33616, detailing an unauthenticated blind SQL injection in the mb24api endpoint caused by improper neutralization of special characters, lacking PoC, exploit code, or active exploitation reports.
