← Vulnerability feed

Vulnerability record · CVE-2026-7489 · published 2 May 2026

CVE-2026-7489: Sun.net ehrd ctms sql injection vulnerability

SSun.Net · Ehrd Ctms

CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

8.7 CVSS 4.0 High EPSS 0.55% · top 56.3% CWE-89 · SQL injection
8.7CVSS 4.0 base score
0.55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-7489 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-54945Sun.net ehrd ctms vulnerabilityAn external control of file name or path vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute…EPSS 0.54%9.8CVE-2024-10440Sun.net ehrd ctms sql injection vulnerabilityThe eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL command to read, modif…EPSS 0.55%9.3CVE-2025-54946Sun.net ehrd ctms sql injection vulnerabilityA SQL injection vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary SQL commands.EPSS 0.48%9.3CVE-2025-54943Sun.net ehrd ctms missing authorization vulnerabilityA missing authorization vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to perform unauthorized app…EPSS 0.50%9.3CVE-2025-54942Sun.net ehrd ctms missing authentication for critical function vulnerabilityA missing authentication for critical function vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to a…EPSS 0.48%8.8CVE-2023-24836Sun.net ehrd ctms path traversal vulnerabilitySUNNET CTMS has vulnerability of path traversal within its file uploading function. An authenticated remote attacker with general user privilege can …EPSS 1.2%8.6CVE-2026-7490Sun.net ehrd cpas unrestricted file upload vulnerabilityCTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell ba…EPSS 0.83%7.5CVE-2024-10438Sun.net ehrd ctms authentication bypass via alternate path vulnerabilityThe eHRD CTMS from Sunnet has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to bypass authentication by satisfyin…EPSS 0.53%

Source: NIST National Vulnerability Database (record CVE-2026-7489), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.