CVE-2026-80236: Thinking Software Technology|Efence - SQL Injection
Published Aug 26, 2026
·Updated
Efence developed by Thinking Software Technology has a SQL Injection vulnerability. Unauthenticated remote attackers can access file upload functionality and read database contents.
Affected Software
1 affected component
Thinking Software Technology Efence
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Efenceto a version that resolves this vulnerability.Fixed in 1.2.67
Event History
Aug 26, 2026
CVE Published
via MITRE·08:27 AM
Data Sourced
via MITRE·08:27 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Unauthenticated remote attackers can exploit the SQL injection vulnerability. No prior account or user interaction is required.
2
What could an attacker access?
An attacker can access the file upload functionality and read database contents. The available information indicates high confidentiality impact and low integrity impact.