CVE-2026-6888 PUBLISHED

SQL Injection Vulnerability

Assigner: CSA
Reserved: 23.04.2026 Published: 13.05.2026 Updated: 13.05.2026

Successful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to execute arbitrary commands via a specific interface, potentially enabling the attacker to access, modify, or delete sensitive information within the database.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7.2

Product Status

Vendor Advantech
Product SaaS Composer
Versions Default: unknown
  • Version prior to version 3.4.17 is affected
Vendor Advantech
Product IoTSuite Growth Linux docker
Versions Default: unknown
  • Version prior to version 2.2.0 is affected
Vendor Advantech
Product IoTSuite Starter Linux docker
Versions Default: unknown
  • Version prior to version 2.2.0 is affected
Vendor Advantech
Product IoT Edge Linux docker
Versions Default: unknown
  • Version prior to version 2.2.0 is affected
Vendor Advantech
Product IoT Edge Windows
Versions Default: unknown
  • Version prior to version 2.2.0 is affected
Vendor Advantech
Product WebAccess/SCADA
Versions Default: unknown
  • Version prior to version 9.2.3 is affected
Vendor Advantech
Product WebAccess SaaS-Composer
Versions Default: unknown
  • Version prior to version 3.4.17.1 is affected
Vendor Advantech
Product ECOWatch SaaS-Composer
Versions Default: unknown
  • Version prior to version 3.4.17 is affected

Solutions

Users and administrators of affected product versions are advised to update to the latest versions immediately.

For SaaS Composer, IoTSuite Growth Linux docker, IoT Edge Windows, and ECOWatch please contact Advantech  here  https://wise-iot.advantech.com/en-tw/marketplace/help/technical-support for the official release of the fixed version.

For IoTSuite Starter Linux docker, please refer to the update guide  here https://portal-kbinsight-wiseiot-ensaas.practice.cloud.advantech.com/kb/library/detail/oPN5exOVNQq . As the update involves a reinstallation process, please refer to the reinstallation guide here https://portal-kbinsight-wiseiot-ensaas.practice.cloud.advantech.com/kb/library/detail/JqNWAMGz1JQ .

For IoT Edge Linux docker, please refer to the update guide  here https://portal-kbinsight-wiseiot-ensaas.practice.cloud.advantech.com/kb/library/detail/oPN5exOVNQq . As the update involves a reinstallation process, please refer to the reinstallation guide here https://portal-kbinsight-wiseiot-ensaas.practice.cloud.advantech.com/kb/library/detail/G0yWBn2mp2q .

For WebAccess/SCADA and WebAccess SaaS-Composer, please refer to the update guide here https://www.advantech.com/en/support/details/installation .

Credits

  • Hoa Ly Van Huu finder

References