{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/cdg-20260615-and-earlier/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-18859"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CDG (20260615 and earlier)"],"_cs_severities":["high"],"_cs_tags":["web-application-vulnerability","sqli","remote-code-execution"],"_cs_type":"threat","_cs_vendors":["ESAFENET"],"content_html":"\u003cp\u003eA high-severity SQL injection vulnerability has been identified in ESAFENET CDG software, affecting versions up to 20260615. The flaw is located within an undisclosed function of the file /CDGServer3/ukey/usbkey;logindojojs. An unauthenticated, remote attacker can manipulate the keyid argument to inject malicious SQL commands, potentially resulting in unauthorized data access or modification. Publicly available exploit code exists, increasing the risk of active exploitation. The vendor has not yet released a patch or responded to disclosure efforts. Defenders should treat this as an immediate risk to any exposed CDG server deployments.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify internet-facing ESAFENET CDG servers.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP GET or POST request targeting the /CDGServer3/ukey/usbkey;logindojojs endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker injects malicious SQL syntax into the keyid parameter, bypassing input sanitization.\u003c/li\u003e\n\u003cli\u003eThe web server process passes the unsanitized parameter to the backend database engine.\u003c/li\u003e\n\u003cli\u003eThe database executes the injected commands within the context of the service account.\u003c/li\u003e\n\u003cli\u003eAttacker extracts sensitive data from the underlying database or modifies application records to maintain persistence or escalate privileges.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to gain unauthorized access to data stored within the CDG database. Depending on the database configuration, this may result in complete data exfiltration, modification, or potential lateral movement within the network. This vulnerability poses a significant risk to organizations using CDG for sensitive document or data protection.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification of all internet-facing ESAFENET CDG installations. Given the lack of a vendor patch, implement strict perimeter filtering to restrict access to the /CDGServer3/ukey/usbkey;logindojojs path. Deploy WAF rules to inspect and block incoming HTTP requests containing SQL injection patterns in the keyid parameter. Monitor web server access logs for anomalous requests to the identified vulnerable endpoint.\u003c/p\u003e\n\u003ch2 id=\"references\"\u003eReferences\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-18859\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-18859\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://vuldb.com/cve/CVE-2026-18859\"\u003ehttps://vuldb.com/cve/CVE-2026-18859\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-05T02:04:14Z","date_published":"2026-08-05T02:04:14Z","id":"https://feed.craftedsignal.io/briefs/2026-08-esafenet-cdg-sqli/","summary":"A publicly exploitable SQL injection vulnerability in ESAFENET CDG allows unauthenticated remote attackers to execute arbitrary database queries via the keyid parameter.","title":"SQL Injection in ESAFENET CDG","url":"https://feed.craftedsignal.io/briefs/2026-08-esafenet-cdg-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - CDG (20260615 and Earlier)","version":"https://jsonfeed.org/version/1.1"}