Project Subscriptions
No data.
No advisories yet.
Solution
The reported vulnerability was fully mitigated by the Nemon team on 26 May 2026. There is no evidence that the vulnerability was exploited, nor that it had any impact on customers or data managed by the platform. As this is a SaaS solution, the fix was applied centrally by Nemon, without requiring any action on the part of customers. The vulnerability has been fixed and is no longer exploitable.
Workaround
No workaround given by the vendor.
Tue, 09 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL injection in the ‘two_steps_auth_code’ parameter processed by the ‘twoStepsAuthVerification’ function within the ‘/user-login’ endpoint. The two-factor authentication (2FA) functionality can be accessed without prior authentication, allowing unauthenticated attackers to execute arbitrary SQL queries on the backend database. A successful exploit could lead to database enumeration, the unauthorised creation of privileged users, the modification or deletion of critical information, and denial-of-service conditions. | |
| Title | SQL injection in Nemon products | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-06-09T14:12:27.775Z
Reserved: 2026-06-03T10:39:45.727Z
Link: CVE-2026-10731
Updated: 2026-06-09T14:12:22.013Z
Status : Deferred
Published: 2026-06-09T10:16:42.820
Modified: 2026-06-09T13:51:18.770
Link: CVE-2026-10731
No data.
OpenCVE Enrichment
Updated: 2026-06-09T11:30:03Z