CVE-2026-6888: Advantech Ecowatch Saas-Composer
High severity, CVSS 7.2. EPSS: 0.7% chance of exploitation in the next 30 days.
Successful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to execute arbitrary commands via a specific interface, potentially enabling the attacker to access, modify, or delete sensitive information within the database.
Affected products
- Advantech Ecowatch Saas-Composer: before 3.4.17 (fixed in 3.4.17)
- Advantech IoT Edge Linux Docker: before 2.2.0 (fixed in 2.2.0)
- Advantech IoT Edge Windows: before 2.2.0 (fixed in 2.2.0)
- Advantech Iotsuite Growth Linux Docker: before 2.2.0 (fixed in 2.2.0)
- Advantech Iotsuite Starter Linux Docker: before 2.2.0 (fixed in 2.2.0)
- Advantech Saas Composer: before 3.4.17 (fixed in 3.4.17)
- Advantech Webaccess/scada: before 9.2.3 (fixed in 9.2.3)
- Advantech Webaccess Saas-Composer: before 3.4.17.1 (fixed in 3.4.17.1)
Published 2026-05-13. Last modified 2026-06-17.