Skip to content
Threat Feed
critical advisory

SQL Injection in Armiya Information Technologies Access Control System

CVE-2026-7188 is a critical SQL injection vulnerability in the Armiya Information Technologies Access Control System versions prior to 2, allowing unauthenticated remote command execution against the backend database.

CVE search metadata

CVE search record: CVE-2026-7188. Severity: critical. CVSS: 9.8. KEV: no. Product: Access Control System (< 2). Brief: SQL Injection in Armiya Information Technologies Access Control System. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2026-7188/

What's new

  • 1. added coverage for Access Control System (< 2) Sep 10, 11:05 via nvd

CVE-2026-7188 describes a critical SQL injection vulnerability identified in the Armiya Information Technologies Ltd. Co. Access Control System. The flaw exists due to improper neutralization of special elements used in SQL commands within the application, allowing an unauthenticated remote attacker to inject and execute arbitrary SQL queries against the underlying database. This vulnerability affects all versions of the Access Control System prior to version 2. Given the nature of the application, successful exploitation could lead to full unauthorized access to sensitive security logs, user credentials, and database contents, potentially resulting in a total compromise of the affected security infrastructure.

Impact

Successful exploitation of this vulnerability allows unauthenticated attackers to manipulate the backend database. This can result in unauthorized data exfiltration, modification of access logs, bypass of authentication mechanisms, or full system compromise. Organizations relying on this access control platform are at high risk of data breach and loss of physical security oversight.

Recommendation

Prioritize the immediate upgrade of all Armiya Information Technologies Access Control System instances to version 2 or later to remediate CVE-2026-7188. Ensure web application logs are monitored for unusual HTTP requests containing SQL syntax, particularly those directed at common entry points for the Access Control System, to detect potential exploitation attempts.


Immediate actions

Upgrade Armiya Information Technologies Access Control System to version 2 or later.

IT Operations 24h

Mitigations

Upgrade Access Control System to version 2.

immediate IT Operations

CVE-2026-7188