CVE-2026-18630 PUBLISHED

SQL Injection in TMT Machine's Talassoft Industrial Management Software

Assigner: TR-CERT
Reserved: 03.08.2026 Published: 01.09.2026 Updated: 01.09.2026

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows SQL Injection.

This issue affects Talassoft Industrial Management Software: from V.4 before V.16.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.8

Product Status

Vendor TMT Machine Industry and Trade Ltd. Co.
Product Talassoft Industrial Management Software
Versions Default: unaffected
  • affected from V.4 to V.16 (excl.)

Credits

  • Efe Özel finder
  • Cemil Sefa Özcan analyst
  • FORDEFENCE sponsor

References

Problem Types

  • CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection') CWE

Impacts

  • CAPEC-66 SQL Injection