External risk intelligence

Smart-web2 Report Module SQL Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-75334

The vulnerability exists in a ReportController interface within a web application's backend. Web applications and their associated controller interfaces are commonly deployed as internet-facing services to facilitate user access to reporting features.

SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in a web application's reporting module that could allow unauthorized access to execute database commands. If exploited, this could potentially lead to a compromise of sensitive information or system disruption. The main concern is to confirm if this specific application is in use and, if so, to assess the exposure.

  • Web application's database commands can be executed.
  • Critical flaw affects data integrity and system access.
  • Confirm relevance and understand potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted request to the report module's save interface. This interface is exposed externally and does not properly validate the `sqlResource.sql` parameter. By injecting malicious SQL code into this parameter, an attacker could gain the ability to execute arbitrary SQL commands on the backend database, potentially leading to data compromise or system control.

  • No authentication required.
  • Triggered by an untrusted parameter.
  • Risk of arbitrary SQL execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to execute arbitrary SQL commands by sending specially crafted requests to the report module's save interface. When this interface is supported by the advisory, such commands could potentially read, modify, or delete data stored within the application's database.

  • Database data could be compromised.
  • Malicious SQL sent via the save interface.
  • Data theft or modification may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

The smart-web2 backend's reporting module is susceptible to SQL injection, posing a critical risk. Application owners and infrastructure teams are likely responsible for remediation. The first step is to identify all instances of smart-web2, assess their reachability and business criticality, and then confirm ownership before planning a risk-based remediation strategy.

  • Identify affected systems and owners.
  • Verify exposure and business criticality.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the smart-web2 software?

Smart-web2 is a web application that includes a backend reporting module designed to manage and store custom report queries. In version 1.3.1, this module provides an interface, known as the ReportController, that allows users to save and execute database queries for reporting purposes.

How does CVE-2026-75334 cause a security risk?

This vulnerability is classified as CWE-89, or Improper Neutralization of Special Elements used in an SQL Command. It happens because the application takes user-provided input and embeds it directly into database queries without any filtering or parameterization. This allows an attacker to manipulate the query structure to execute unauthorized commands.

Do I need to be logged in to trigger this flaw?

No, authentication is not required to trigger this vulnerability. The flaw exists because the ReportController.save() interface accepts untrusted input from the network. It is not triggered by standard application use, but specifically by sending a crafted request that injects malicious SQL code into the sqlResource.sql parameter.

Why is this CVE considered relevant to my infrastructure?

According to Halo Surface Signal, this vulnerability is highly relevant because the affected reporting module is typically deployed as an internet-facing service to allow easy user access. Because the interface is reachable from the network, an attacker does not need prior access to your internal environment to attempt an exploit.

When should I begin my response to this advisory?

You should start by identifying all instances of smart-web2 version 1.3.1 within your environment. Once you have a complete inventory, verify if these systems are reachable from the internet or restricted to internal networks. Finally, coordinate with the business owners of those specific systems to prioritize risk and prepare for updates.

References