CVE-2026-33617: MB connect line mbCONNECT24 vulnerable to an unauthenticated information disclosure in the data24 Endpoint
An unauthenticated remote attacker can access a configuration file containing database credentials. This can result in a some loss of confidentiality, but there is no endpoint exposed to use these credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33617?
CVE-2026-33617 is classified with a low severity due to the potential information disclosure of sensitive configuration files.
How do I fix CVE-2026-33617?
To fix CVE-2026-33617, you should immediately restrict access to the data24 endpoint and review your configuration file permissions.
What data is exposed in CVE-2026-33617?
CVE-2026-33617 allows unauthorized access to a configuration file that includes sensitive database credentials.
Is authentication required to exploit CVE-2026-33617?
No authentication is required to exploit CVE-2026-33617, making it particularly dangerous.
Which versions of mbCONNECT24 are affected by CVE-2026-33617?
CVE-2026-33617 affects all versions of mbCONNECT24 up to and including version 2.19.4.