{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/goldenhorn-oneit--g%C3%B6beklitepe/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:tac_information_services:goldenhorn_oneit:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-18198"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GOLDENHORN ONEIT (\u003c Göbeklitepe)"],"_cs_severities":["high"],"_cs_tags":["web-application-vulnerability","sql-injection","cve-2026-18198"],"_cs_type":"advisory","_cs_vendors":["TAC Information Services"],"content_html":"\u003cp\u003eCVE-2026-18198 is a blind SQL injection vulnerability affecting the TAC Information Services GOLDENHORN ONEIT platform. The vulnerability is caused by improper neutralization of special elements within SQL commands, enabling unauthorized actors to manipulate database queries. This flaw resides in versions prior to the Göbeklitepe release. Successful exploitation allows an attacker to interact with the backend database, potentially leading to unauthorized data exfiltration, modification of application logic, or complete compromise of the database integrity. Because the vulnerability is blind in nature, attackers typically leverage time-based or boolean-based inference techniques to extract data, making the activity subtle and difficult to detect without specialized web application firewall or database auditing logs.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability carries a CVSS v3.1 base score of 8.8, indicating a high level of risk to confidentiality and integrity. If exploited, an attacker could extract sensitive information stored in the application database or bypass authentication mechanisms. The scope of impact includes all organizations currently running versions of GOLDENHORN ONEIT earlier than the Göbeklitepe release.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePatch immediately by upgrading all instances of GOLDENHORN ONEIT to the Göbeklitepe release or later.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous SQL syntax, such as sleep functions, binary operators, or unexpected union statements, directed at the GOLDENHORN ONEIT application.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation and parameterized queries at the application level to mitigate against SQL injection vectors.\u003c/li\u003e\n\u003cli\u003eDeploy WAF rules configured to detect and block common SQL injection patterns (e.g., OR 1=1, UNION SELECT, WAITFOR DELAY) targeting application endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T13:26:42Z","date_published":"2026-09-04T13:26:42Z","id":"https://feed.craftedsignal.io/briefs/2026-09-goldenhorn-sqli/","summary":"A blind SQL injection vulnerability (CVE-2026-18198) in TAC Information Services GOLDENHORN ONEIT allows unauthenticated attackers to execute arbitrary SQL queries.","title":"Blind SQL Injection Vulnerability in GOLDENHORN ONEIT","url":"https://feed.craftedsignal.io/briefs/2026-09-goldenhorn-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - GOLDENHORN ONEIT (\u003c Göbeklitepe)","version":"https://jsonfeed.org/version/1.1"}