CVE-2026-6881 PUBLISHED

Authenticated SQL Injection Enables Unauthorized Access to Sensitive Information in Ellucian Advance Web and Legacy Advance

Assigner: SRA
Reserved: 22.04.2026 Published: 28.07.2026 Updated: 29.07.2026

A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field.

This issue affects Advance Web: all versions; Legacy Advance: all versions.

Ellucian CRM Advance is not impacted.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L
CVSS Score: 9.4

Product Status

Vendor Ellucian
Product Advance Web
Versions Default: affected
  • affected from 0 to * (incl.)
Vendor Ellucian
Product Legacy Advance
Versions Default: affected
  • affected from 0 to * (incl.)

Credits

  • Jeremy Slaven (SRA) finder
  • Dylan Eliasson (SRA) finder
  • Mark Blaho (SRA) finder

References

Problem Types

  • CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection') CWE

Impacts

  • CAPEC-66 SQL Injection