OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-12718

CRITICAL · CVSS 9.8 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

KarelIPS is vulnerable to a critical SQL injection flaw that allows attackers to execute blind SQL injection attacks, potentially compromising the integrity and confidentiality of the database. Organizations using this product should prioritize remediation efforts, as the lack of vendor support increases the risk of exploitation. Immediate action is essential to mitigate potential data breaches and unauthorized access.

CVE
CVE-2026-12718
Severity
CRITICAL
CVSS
9.8
EPSS
0.32%

Original NVD Description

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Karel Electronic Industry and Trade Inc. KarelIPS allows Blind SQL Injection. This issue affects KarelIPS: through 22092026. NOTE: The vendor was contacted and it was learned that the product is not supported.