SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-6881

CRITICAL · CVSS 9.4 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-07-28 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

A SQL Injection vulnerability in the Giving Reports functionality of both Ellucian Advance Web and Legacy Advance allows authenticated attackers to execute crafted SQL queries, potentially leading to the extraction of sensitive information from databases. Organizations using these affected versions should prioritize remediation efforts to mitigate the risk of data breaches. Ellucian CRM Advance users are not impacted by this vulnerability.

CVE
CVE-2026-6881
Severity
CRITICAL
CVSS
9.4
EPSS
0.20%

Original NVD Description

A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field. This issue affects Advance Web: all versions; Legacy Advance: all versions. Ellucian CRM Advance is not impacted.