SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-51366

CRITICAL · CVSS 9.9 EPSS 0.55%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Bottinelli Informatica Vedo Suite v.1.2.5 is vulnerable to SQL Injection through the api_vedo/chat endpoint, allowing remote attackers to execute arbitrary code by manipulating the utente_chat parameter. Organizations utilizing this software should prioritize remediation to prevent potential unauthorized access and exploitation of their systems. Immediate attention is recommended for those handling sensitive data or operating in regulated environments.

CVE
CVE-2026-51366
Severity
CRITICAL
CVSS
9.9
EPSS
0.55%

Original NVD Description

SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to execute arbitrary code via the api_vedo/chat endpoint and the utente_chat parameter