CVE-2026-18859: ESAFENET CDG usbkey;logindojojs sql injection
A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of the file /CDGServer3/ukey/usbkey;logindojojs. Such manipulation of the argument keyid leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18859?
The severity of CVE-2026-18859 is high with a score of 7.3.
What type of vulnerability is CVE-2026-18859?
CVE-2026-18859 is classified as an SQL Injection vulnerability.
How do I fix CVE-2026-18859?
To fix CVE-2026-18859, update your ESAFENET CDG software to a version released after 20260615.
Can CVE-2026-18859 be exploited remotely?
Yes, CVE-2026-18859 can be exploited from a remote location.
What is affected by CVE-2026-18859?
CVE-2026-18859 affects the function handling the file /CDGServer3/ukey/usbkey;logindojojs in ESAFENET CDG.