
🚨 HIGH: CVE-2026-40522 (CVSS 7.1) - SQL Injection in FrontAccounting <2[.]4[.]20 allows authenticated attackers to extract usernames, password hashes & emails via Bank Statement report handler. Patch immediately. #CVE #PatchNow #ThreatIntel https://t.co/4tJVD1fDSQ
Post summary
The tweet warns of a high‑severity SQL injection vulnerability (CVE‑2026‑40522) in FrontAccounting that allows authenticated attackers to retrieve user credentials, stresses the need for immediate patching, and provides specific technical details.
