SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-66649

CRITICAL · CVSS 9.3 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

An unauthenticated SQL injection vulnerability exists in Directory Pro versions up to 2.5.8, allowing attackers to manipulate database queries and potentially gain unauthorized access to sensitive data. The critical severity of this flaw (CVSS 9.3) necessitates immediate attention from organizations using affected versions, particularly those handling sensitive information or user data. It is essential for system administrators and security teams to prioritize patching or mitigating this vulnerability to prevent exploitation.

CVE
CVE-2026-66649
Severity
CRITICAL
CVSS
9.3
EPSS
0.29%

Original NVD Description

Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.