CVE-2026-40529 PUBLISHED

Assigner: jpcert
Reserved: 13.04.2026 Published: 23.04.2026 Updated: 23.04.2026

CMS ALAYA provided by KANATA Limited contains an SQL injection vulnerability. Information stored in the database may be obtained or altered by an attacker with access to the administrative interface.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
CVSS Score: 5.1

Product Status

Vendor KANATA Limited
Product CMS ALAYA
Versions
  • Version 7.4.1.4 and earlier is affected

References

Problem Types