CVE-2026-8402 PUBLISHED

SQLi in Exagate's SYSGUARD 6001

Assigner: TR-CERT
Reserved: 12.05.2026 Published: 30.06.2026 Updated: 30.06.2026

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. SYSGUARD 6001 allows Blind SQL Injection.

This issue affects SYSGUARD 6001: from 2.0.2 before 6.1.16.0.  NOTE: The vendor was contacted and it was learned that the product is not supported.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor Eksagate Electronic Engineering and Computer Industry Trade Inc.
Product SYSGUARD 6001
Versions Default: unaffected
  • affected from 2.0.2 to 6.1.16.0 (excl.)

Credits

  • Talha YILDIZ finder

References

Problem Types

  • CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection') CWE

Impacts

  • CAPEC-7 Blind SQL Injection