<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:teracity:e-Osb:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3ateracitye-osb/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 01 Sep 2026 15:06:32 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3ateracitye-osb/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SQL Injection Vulnerability in Teracity E-OSB</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-18765/</link><pubDate>Tue, 01 Sep 2026 15:06:32 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-18765/</guid><description>Teracity E-OSB versions prior to V02.26.07.08.01 contain an SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL commands against the backend database.</description><content:encoded><![CDATA[<p>Teracity Software Technologies Inc. E-OSB is vulnerable to SQL injection (CVE-2026-18765) due to improper neutralization of special elements used in SQL commands. This vulnerability allows an unauthenticated remote attacker to inject malicious SQL statements through crafted input fields. Successful exploitation could lead to unauthorized access to sensitive data, modification of application records, or potential administrative control over the underlying database. The vulnerability affects all versions of E-OSB released prior to V02.26.07.08.01. Organizations utilizing this platform should prioritize updating to the patched version immediately to mitigate the risk of data exfiltration or integrity compromise.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability carries a CVSS v3.1 base score of 9.8, indicating a critical severity. Exploitation allows unauthenticated actors to bypass authentication or manipulate database records. Depending on the database permissions and configuration, this could result in full data exfiltration, system compromise, or complete loss of database availability.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update all deployments of Teracity E-OSB to version V02.26.07.08.01 or later to remediate CVE-2026-18765.</p>
<ul>
<li>Upgrade the affected application to version V02.26.07.08.01 immediately.</li>
<li>Monitor web application firewall logs for SQL injection signatures targeting the E-OSB application.</li>
<li>Audit database logs for anomalous queries or unauthorized access patterns initiated by the E-OSB service account.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>sql-injection</category><category>vulnerability</category><category>web-application</category></item></channel></rss>