CVE-2026-89180: Thinking Software Technology|EFence - SQL Injection
Published Sep 14, 2026
·Updated
EFence developed by Thinking Software Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.
Affected Software
1 affected component
Thinking Software Technology Efence
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
EFenceto a version that resolves this vulnerability.Fixed in 1.2.67
Event History
Sep 14, 2026
CVE Published
via MITRE·10:27 AM
Data Sourced
via MITRE·10:27 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Unauthenticated remote attackers can exploit it over the network. No credentials or user interaction are required.
2
What is the likely impact of successful exploitation?
An attacker can inject arbitrary SQL commands and read database contents. The provided impact information indicates high confidentiality impact, with no stated integrity or availability impact.