CVE-2026-1432: T-Systems Buroweb
Critical severity, CVSS 9.3. EPSS: 0.4% chance of exploitation in the next 30 days.
SQL injection vulnerability in the Buroweb platform version 2505.0.12, specifically in the 'tablon' component. This vulnerability is present in several parameters that do not correctly sanitize user input in the endpoint '/sta/CarpetaPublic/doEvent?APP_CODE=STA&PAGE_CODE=TABLON'. Exploiting this vulnerability could allow an attacker to execute queries on the database and gain access to confidential information.
Affected products
- T-Systems Buroweb: before 2505.0.13 (fixed in 2505.0.13)
Published 2026-02-03. Last modified 2026-06-17.