CVE-2026-40522Patch

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Bank Statement report handler that allows authenticated attackers to extract arbitrary database data by injecting UNION SELECT payloads into the PARAM_0 POST parameter. Attackers can supply malicious SQL syntax through the unparameterized WHERE clause to retrieve sensitive information including usernames, password hashes, and email addresses from the users table, rendered into PDF report output.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89CWE-916

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-30: 1Patch / Workaround · 2026-06-30: 1Technical Details · 2026-06-30: 106-30
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-40522 (CVSS 7.1) - SQL Injection in FrontAccounting <2[.]4[.]20 allows authenticated attackers to extract usernames, password hashes & emails via Bank Statement report handler. Patch immediately. #CVE #PatchNow #ThreatIntel https://t.co/4tJVD1fDSQ

    Post summary

    The tweet warns of a high‑severity SQL injection vulnerability (CVE‑2026‑40522) in FrontAccounting that allows authenticated attackers to retrieve user credentials, stresses the need for immediate patching, and provides specific technical details.

    0000056
    55 followersView on X

Explore more