OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-107103 (CVSS 9.3)

NVD · officialPublished Oct 7, 2026Risk 50/100

This vulnerability exists in the ERP system due to insufficient validation and parameterization of user supplied input in an API endpoint. An unauthenticated remote attacker could exploit this vulnerability by supplying specially crafted input to the vulnerable endpoint. Successful exploitation of this vulnerability could allow the attacker to perform SQL injection attacks on the targeted system.

CVSS
9.3
AV:NetworkAC:LowPR:NoneUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source