CVE-2026-68068: Toptech TMS7 and TopHAT SQL Injection
Published Sep 29, 2026
·Updated
The "screenID" parameter in the electronic transaction queue viewer feature within the manual transactions section is susceptible to a time-based blind SQL injection vulnerability.
Affected Software
2 affected components
Toptech TMS7
Toptech TopHAT
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Toptech TMS7 and TopHATto a version that resolves this vulnerability.Fixed in 7.8
Event History
Sep 29, 2026
CVE Published
via MITRE·09:33 PM
Data Sourced
via MITRE·09:33 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attacker needs high privileges in the affected application. Exploitation does not require user interaction.
2
Can the vulnerability be exploited over the network?
Yes. The attack vector is network-based and has low attack complexity.
3
What is the potential security impact?
The vulnerability is rated critical and can affect components beyond the initially vulnerable security authority. It has high confidentiality and availability impact, and low integrity impact.