CVE-2026-10521: Mb Connect Line MBCONNECT24

High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.

An high privileged remote attacker can access a hidden configuration method, that should not be accessible by any user, to modify critical program parameters. This can result in a total loss of confidentiality, integrity and availability.

Affected products

  • Mb Connect Line MBCONNECT24: from 0.0.0, before 2.20.2 (fixed in 2.20.2); version 2.20.1 only
  • Mb Connect Line MYMBCONNECT24: from 0.0.0, before 2.20.2 (fixed in 2.20.2); version 2.20.1 only

Published 2026-06-23. Last modified 2026-06-23.