CVE-2026-72507: Toptech TMS7 and TopHAT SQL Injection
Published Sep 29, 2026
·Updated
The "reportType" parameter in the product summary report feature within the balancing reports section is susceptible to a time-based blind SQL injection vulnerability.
Affected Software
2 affected components
Toptech TMS7
Toptech TopHAT
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Toptech TMS7to a version that resolves this vulnerability.Fixed in 7.8
Event History
Sep 29, 2026
CVE Published
via MITRE·09:36 PM
Data Sourced
via MITRE·09:36 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attack vector is network-based, but exploitation requires high privileges. No user interaction is required.
2
What is the potential impact if exploitation succeeds?
The vulnerability is rated critical and may result in high confidentiality and availability impact, with low integrity impact. The scoring vector also indicates that the impact can extend beyond the vulnerable component's security authority.