Skip to content
CVSS 8.8 · HIGH

CVE-2026-7489

CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

View on NVD

Analysis

This is an authenticated SQL injection vulnerability in a specialized Clinical Trial Management System (CTMS) developed by Sunnet. It affects a niche vertical market rather than widely used developer tooling or infrastructure, and requires authentication to exploit.

Severity

Score: 8.8(HIGH)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: LOW
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-89

EPSS

Probability of exploitation (next 30 days): 0.0008 (0.1%)
Percentile: 23.4%
EPSS: 2026-05-06

Technical description

CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

Published: 5/2/2026, 10:16:18 AM
Last modified: 5/5/2026, 8:14:57 PM

References

HomeEventsBlogResourcesTeam