CVE-2026-53690Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An SQL Injection vulnerability exists in Redeight CMS version 1.0 via the "userEmail" parameter in the POST "/admin/index.php" login endpoint. The application fails to sanitize user input and directly interpolates it into SQL queries without using prepared statements, which allows unauthenticated remote attackers to execute arbitrary SQL commands and extract sensitive database information.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-30: 3Technical Details · 2026-06-30: 306-30
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Unauthenticated SQL Injection in Redeight CMS admin login (CVE-2026-53690) Redeight CMS 1.0 is vulnerable to SQL injection in the POST /admin/index.php login endpoint via the userEmail parameter, allowing hostile input to reach the database layer. The root cause is improper input validation and unsafe SQL query construction (string interpolation without prepared statements). An unauthenticated remote attacker can exploit this over the network by sending crafted POST requests to manipulate backend SQL execution during authentication. Successful exploitation can expose sensitive database contents and potentially enable broader compromise through credential disclosure and database tampering. 👉 Affected: Redeight CMS 1.0 | Upgrade to No fix yet — treat as suspicious

    Post summary

    Redeight CMS 1.0 is vulnerable to unauthenticated SQL injection in the admin login endpoint; detailed technical information is provided, but no PoC, exploit, patch, or evidence of active exploitation is present.

    0000056
    232 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-53690 An SQL Injection vulnerability exists in Redeight CMS version 1.0 via the "userEmail" parameter in the POST "/admin/index.php" login endpoint. The application fails t… https://www.cve.org/CVERecord?id=CVE-2026-53690 ----- Traducción: CVE-2026-53690 Exi… http://infoflow.cloud`

    Post summary

    The post discloses a new SQL Injection vulnerability (CVE‑2026‑53690) affecting Redeight CMS 1.0, providing specific details such as the exploited parameter and endpoint, but does not mention exploitation, patches or PoC.

    0000029
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-53690 An SQL Injection vulnerability exists in Redeight CMS version 1.0 via the "userEmail" parameter in the POST "/admin/index.php" login endpoint. The application fails t… https://www.cve.org/CVERecord?id=CVE-2026-53690

    Post summary

    The post discloses an SQL injection vulnerability in Redeight CMS version 1.0 (CVE‑2026‑53690) affecting the userEmail parameter of the admin login endpoint.

    00000800
    57.7K followersView on X

Explore more