Skip to content
Threat Feed
critical advisory

SQL Injection Vulnerability in Teracity E-OSB

Teracity E-OSB versions prior to V02.26.07.08.01 contain an SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL commands against the backend database.

CVE search metadata

CVE search record: CVE-2026-18765. Severity: critical. CVSS: 9.8. KEV: no. Product: E-OSB (< V02.26.07.08.01). Brief: SQL Injection Vulnerability in Teracity E-OSB. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2026-18765/

Teracity Software Technologies Inc. E-OSB is vulnerable to SQL injection (CVE-2026-18765) due to improper neutralization of special elements used in SQL commands. This vulnerability allows an unauthenticated remote attacker to inject malicious SQL statements through crafted input fields. Successful exploitation could lead to unauthorized access to sensitive data, modification of application records, or potential administrative control over the underlying database. The vulnerability affects all versions of E-OSB released prior to V02.26.07.08.01. Organizations utilizing this platform should prioritize updating to the patched version immediately to mitigate the risk of data exfiltration or integrity compromise.

Impact

The vulnerability carries a CVSS v3.1 base score of 9.8, indicating a critical severity. Exploitation allows unauthenticated actors to bypass authentication or manipulate database records. Depending on the database permissions and configuration, this could result in full data exfiltration, system compromise, or complete loss of database availability.

Recommendation

Update all deployments of Teracity E-OSB to version V02.26.07.08.01 or later to remediate CVE-2026-18765.

  • Upgrade the affected application to version V02.26.07.08.01 immediately.
  • Monitor web application firewall logs for SQL injection signatures targeting the E-OSB application.
  • Audit database logs for anomalous queries or unauthorized access patterns initiated by the E-OSB service account.

Mitigations

Upgrade E-OSB to V02.26.07.08.01

immediate IT Operations

CVE-2026-18765