CVE-2026-55721Patch

LOWCVSS 9.2 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Storage Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl and debug.pl scripts. The cookie value is incorporated directly into database queries without adequate sanitization, allowing an unauthenticated remote attacker to manipulate those queries and extract sensitive information from the underlying database, including session tokens, password hashes, and stored secret keys.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-01: 1Patch / Workaround · 2026-07-01: 1Technical Details · 2026-07-01: 107-01
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-55721 (CVSS 9.3) Storage Concentrator (SC & SCVM) SQL injection via cookie values. Unauthenticated remote attackers can extract session tokens, password hashes & secret keys. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/BhWyfH7NDf

    Post summary

    Critical SQL injection (CVE-2026-55721) in Storage Concentrator allows unauthenticated attackers to retrieve session tokens, password hashes, and secret keys, requiring an immediate patch.

    0000051
    56 followersView on X

Explore more