CVE-2026-72510: Toptech TMS7 and TopHAT SQL Injection
Published Sep 29, 2026
·Updated
The "supplierno" parameter used in the business allocation search feature is vulnerable to time-based blind SQL injection.
Affected Software
2 affected components
Toptech TMS7
Toptech TopHAT
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Toptech TMS7to a version that resolves this vulnerability.Fixed in 7.8
Event History
Sep 29, 2026
CVE Published
via MITRE·09:28 PM
Data Sourced
via MITRE·09:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker must already have high privileges and be able to reach the affected functionality over the network. No user interaction is required.
2
What could a successful exploit allow?
The reported impact includes high confidentiality impact, low integrity impact, and high availability impact. The vulnerability is rated critical with a score of 9.