{"api_version":"1","generated_at":"2026-09-13T13:31:09+00:00","cve":"CVE-2026-18630","urls":{"html":"https://cve.report/CVE-2026-18630","api":"https://cve.report/api/cve/CVE-2026-18630.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-18630","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-18630"},"summary":{"title":"SQL Injection in TMT Machine's Talassoft Industrial Management Software","description":"Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows SQL Injection.\n\nThis issue affects Talassoft Industrial Management Software: from V.4 before V.16.","state":"PUBLISHED","assigner":"TR-CERT","published_at":"2026-09-01 15:17:12","updated_at":"2026-09-01 21:10:38"},"problem_types":["CWE-89","CWE-89 CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection')"],"metrics":[{"version":"3.1","source":"iletisim@usom.gov.tr","type":"Secondary","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0965","name":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0965","refsource":"iletisim@usom.gov.tr","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-18630","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18630","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"TMT Machine Industry and Trade Ltd. Co.","product":"Talassoft Industrial Management Software","version":"affected V.4 V.16 custom","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Efe Özel","lang":"en"},{"source":"CNA","value":"Cemil Sefa Özcan","lang":"en"},{"source":"CNA","value":"FORDEFENCE","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"18630","cve":"CVE-2026-18630","epss":"0.002950000","percentile":"0.216320000","score_date":"2026-09-03","updated_at":"2026-09-04 00:08:06"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-18630","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-09-01T15:21:34.762413Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-01T15:21:49.187Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Talassoft Industrial Management Software","vendor":"TMT Machine Industry and Trade Ltd. Co.","versions":[{"lessThan":"V.16","status":"affected","version":"V.4","versionType":"custom"}]}],"credits":[{"lang":"en","type":"finder","value":"Efe Özel"},{"lang":"en","type":"analyst","value":"Cemil Sefa Özcan"},{"lang":"en","type":"sponsor","value":"FORDEFENCE"}],"datePublic":"2026-09-01T15:06:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows SQL Injection.<p>This issue affects Talassoft Industrial Management Software: from V.4 before V.16.</p>"}],"value":"Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows SQL Injection.\n\nThis issue affects Talassoft Industrial Management Software: from V.4 before V.16."}],"impacts":[{"capecId":"CAPEC-66","descriptions":[{"lang":"en","value":"CAPEC-66 SQL Injection"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-89","description":"CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-01T15:08:50.285Z","orgId":"ca940d4e-fea4-4aa2-9a58-591a58b1ce21","shortName":"TR-CERT"},"references":[{"tags":["government-resource"],"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0965"}],"source":{"advisory":"TR-26-0965","defect":["TR-26-0965"],"discovery":"UNKNOWN"},"title":"SQL Injection in TMT Machine's Talassoft Industrial Management Software","x_generator":{"engine":"Vulnogram 1.0.5"}}},"cveMetadata":{"assignerOrgId":"ca940d4e-fea4-4aa2-9a58-591a58b1ce21","assignerShortName":"TR-CERT","cveId":"CVE-2026-18630","datePublished":"2026-09-01T15:08:50.285Z","dateReserved":"2026-08-03T09:24:46.122Z","dateUpdated":"2026-09-01T15:21:49.187Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-01 15:17:12","lastModifiedDate":"2026-09-01 21:10:38","problem_types":["CWE-89","CWE-89 CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection')"],"metrics":{"cvssMetricV31":[{"source":"iletisim@usom.gov.tr","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-01T15:21:34.762413Z","id":"CVE-2026-18630","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"18630","Ordinal":"1","Title":"SQL Injection in TMT Machine's Talassoft Industrial Management S","CVE":"CVE-2026-18630","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"18630","Ordinal":"1","NoteData":"Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows SQL Injection.\n\nThis issue affects Talassoft Industrial Management Software: from V.4 before V.16.","Type":"Description","Title":"SQL Injection in TMT Machine's Talassoft Industrial Management S"}]}}}