PT-2026-20834 · Unknown · Databank Accreditation

Published

2026-02-19

·

Updated

2026-02-19

·

CVE-2025-9953

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Databank Accreditation Software versions through 19022026
Description The software contains an authorization bypass issue resulting from a user-controlled SQL primary key flaw. This allows for SQL injection attacks that can bypass authorization controls, potentially leading to unauthorized access and manipulation of sensitive data. The vendor was contacted regarding this issue but did not respond.
Recommendations Versions through 19022026 require attention to address the authorization bypass issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2025-9953

Affected Products

Databank Accreditation