CRITICAL 9.1 CVE-2026-51346 Published 17 Aug 2026

StudIP SQL Injection Vulnerability Allows Remote Code Execution

Worried this affects one of your servers?

A SQL Injection vulnerability has been found in StudIP versions 6.0.x before 6.0.3 and 5.4.x before 5.4.12.

The flaw exists in the store() functions and allows a remote attacker to execute arbitrary code and obtain sensitive information.

  • Affected versions: StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12
  • Attack vector: remote
  • Impact: arbitrary code execution and sensitive information disclosure

Reference: CVE-2026-51346 on NVD

← Back to Security News