CVE-2026-6888: Advantech Ecowatch Saas-Composer

High severity, CVSS 7.2. EPSS: 0.7% chance of exploitation in the next 30 days.

Successful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to execute arbitrary commands via a specific interface, potentially enabling the attacker to access, modify, or delete sensitive information within the database.

Affected products

  • Advantech Ecowatch Saas-Composer: before 3.4.17 (fixed in 3.4.17)
  • Advantech IoT Edge Linux Docker: before 2.2.0 (fixed in 2.2.0)
  • Advantech IoT Edge Windows: before 2.2.0 (fixed in 2.2.0)
  • Advantech Iotsuite Growth Linux Docker: before 2.2.0 (fixed in 2.2.0)
  • Advantech Iotsuite Starter Linux Docker: before 2.2.0 (fixed in 2.2.0)
  • Advantech Saas Composer: before 3.4.17 (fixed in 3.4.17)
  • Advantech Webaccess/scada: before 9.2.3 (fixed in 9.2.3)
  • Advantech Webaccess Saas-Composer: before 3.4.17.1 (fixed in 3.4.17.1)

Published 2026-05-13. Last modified 2026-06-17.