SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-80236

HIGH · CVSS 8.2 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability in Efence allows unauthenticated remote attackers to exploit a SQL Injection flaw, enabling them to access file upload functionalities and potentially read sensitive database contents. Organizations using this software should prioritize remediation efforts due to the high severity of the issue, which poses significant risks to data confidentiality and integrity. Immediate action is recommended to mitigate the threat of unauthorized data exposure.

CVE
CVE-2026-80236
Severity
HIGH
CVSS
8.2
EPSS
0.37%

Original NVD Description

Efence developed by Thinking Software Technology has a SQL Injection vulnerability. Unauthenticated remote attackers can access file upload functionality and read database contents.