CVE-2026-2236: HGiga|C&Cm@il - SQL Injection
Published Feb 9, 2026
·Updated
C&Cm@il developed by HGiga has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.
Affected Software
1 affected component
Hgiga C&Cm@il
Remediation
Information
Update package olln-base to version 7.0-978 or later.
Event History
Feb 9, 2026
CVE Published
via MITRE·07:20 AM
Data Sourced
via MITRE·07:20 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-2236?
CVE-2026-2236 has a high severity level due to its potential for unauthorized access to sensitive data.
2
How do I fix CVE-2026-2236?
To fix CVE-2026-2236, ensure proper input validation and use prepared statements to prevent SQL injection attacks.
3
Who is affected by CVE-2026-2236?
CVE-2026-2236 affects users of the HGiga C&Cm@il software that is vulnerable to SQL injection.
4
What types of data can be compromised in CVE-2026-2236?
CVE-2026-2236 allows attackers to potentially read sensitive database contents, including user data.
5
Is CVE-2026-2236 actively being exploited?
While there is no public evidence of active exploitation for CVE-2026-2236, the vulnerability poses a significant risk to unpatched systems.