Skip to content
Threat Feed
high advisory

SQL Injection Vulnerability in Iron Mountain enVision

CVE-2026-86595 is an SQL injection vulnerability in Iron Mountain enVision versions prior to 260655 that allows unauthenticated attackers to execute arbitrary SQL commands against the backend database.

CVE search metadata

CVE search record: CVE-2026-86595. Severity: high. CVSS: 8.8. KEV: no. Product: enVision (< 260655). Brief: SQL Injection Vulnerability in Iron Mountain enVision. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2026-86595/

CVE-2026-86595 describes an SQL injection (SQLi) vulnerability affecting Iron Mountain enVision services. The vulnerability is caused by improper neutralization of special elements within SQL queries, which allows an attacker to inject arbitrary SQL commands. This flaw can be exploited by an unauthenticated remote attacker to gain unauthorized access to the underlying database, potentially resulting in data exfiltration, modification, or deletion. The vulnerability affects all versions of enVision prior to 260655. Defenders should identify all internet-facing instances of enVision and apply the vendor-provided security updates to mitigate the risk of exploitation.

Impact

Successful exploitation of this vulnerability allows unauthorized access to sensitive archived data managed by the enVision platform. Depending on the database permissions and configuration, an attacker could potentially extract the entire contents of the database, modify stored records, or gain deeper access into the hosting environment. Organizations relying on enVision for regulatory compliance or long-term data storage face significant risk of data breach and integrity loss if this flaw is exploited.

Recommendation

Prioritize the immediate patching of all deployed instances of enVision. Upgrade the application to version 260655 or the latest available version provided by Iron Mountain. Monitor web application firewall (WAF) logs for suspicious SQL injection patterns, such as the presence of common SQL keywords (e.g., UNION, SELECT, OR 1=1) within URI parameters or request headers directed at enVision services. Given the nature of SQLi, auditing database access logs for unusual queries originating from the application service account is also recommended to detect potential post-exploitation activity.


Immediate actions

Upgrade Iron Mountain enVision to version 260655 or later.

IT Operations 48h

Mitigations

Upgrade Iron Mountain enVision to 260655.

immediate IT Operations

CVE-2026-86595