SQL Injection Vulnerability in Iron Mountain enVision
CVE-2026-86595 is an SQL injection vulnerability in Iron Mountain enVision versions prior to 260655 that allows unauthenticated attackers to execute arbitrary SQL commands against the backend database.
CVE search metadata
CVE search record: CVE-2026-86595. Severity: high. CVSS: 8.8. KEV: no. Product: enVision (< 260655). Brief: SQL Injection Vulnerability in Iron Mountain enVision. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2026-86595/
CVE-2026-86595 describes an SQL injection (SQLi) vulnerability affecting Iron Mountain enVision services. The vulnerability is caused by improper neutralization of special elements within SQL queries, which allows an attacker to inject arbitrary SQL commands. This flaw can be exploited by an unauthenticated remote attacker to gain unauthorized access to the underlying database, potentially resulting in data exfiltration, modification, or deletion. The vulnerability affects all versions of enVision prior to 260655. Defenders should identify all internet-facing instances of enVision and apply the vendor-provided security updates to mitigate the risk of exploitation.
Impact
Successful exploitation of this vulnerability allows unauthorized access to sensitive archived data managed by the enVision platform. Depending on the database permissions and configuration, an attacker could potentially extract the entire contents of the database, modify stored records, or gain deeper access into the hosting environment. Organizations relying on enVision for regulatory compliance or long-term data storage face significant risk of data breach and integrity loss if this flaw is exploited.
Recommendation
Prioritize the immediate patching of all deployed instances of enVision. Upgrade the application to version 260655 or the latest available version provided by Iron Mountain. Monitor web application firewall (WAF) logs for suspicious SQL injection patterns, such as the presence of common SQL keywords (e.g., UNION, SELECT, OR 1=1) within URI parameters or request headers directed at enVision services. Given the nature of SQLi, auditing database access logs for unusual queries originating from the application service account is also recommended to detect potential post-exploitation activity.
Immediate actions
Upgrade Iron Mountain enVision to version 260655 or later.
Mitigations
Upgrade Iron Mountain enVision to 260655.
CVE-2026-86595