cve.akaoma.com Critical SQL Injection Vulnerability in UMAI Vision Traffic Analysis System (CVE-2026-4978)
Article Content
- •CVE-2026-4978 is a critical SQL injection vulnerability with a CVSS score of 9.8.
- •The vulnerability affects UMAI Vision Traffic Analysis System versions 30 to 33.
- •No evidence of active exploitation has been reported, but immediate patching is recommended.
A critical SQL injection vulnerability, CVE-2026-4978, has been identified in the UMAI Vision Traffic Analysis System, affecting versions 30 to 33. This flaw allows unauthenticated attackers to execute arbitrary SQL commands remotely, leading to potential unauthorized access, data modification, or deletion. The vulnerability has been assigned a CVSS score of 9.8, indicating its critical severity. Currently, there is no evidence of active exploitation or public proof-of-concept. A patch is available for users to upgrade to a version beyond 33. Security experts recommend implementing network-level access controls and monitoring database query logs for suspicious activity. Organizations using the affected system are urged to take immediate action to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track CVE-2026-4978 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…