CVE-2026-18912: Authenticated SQL injection vulnerability in DataSecurity Plus

Vulnerability details
Severity High
CVE ID CVE-2026-18912
Affected software versions 6300 and earlier
Fixed version 6310
Fixed on Aug. 6, 2026

Details

An authenticated SQL injection vulnerability in reports module where an authenticated technician could execute arbitrary SQL queries.

Impact

This vulnerability could allow an authenticated attacker to execute arbitrary SQL queries, resulting in loss of data integrity.

Fix

The issue is fixed by strengthening input sanitization for all filter types and expanding SQL escaping coverage to ensure user-provided values are consistently processed before query construction.

Steps to update

If your DataSecurity Plus installation build version is below 6310, we highly recommend upgrading to the latest version as soon as possible using the service pack.

Acknowledgements

  • This issue was reported by qquynh through the Zoho BugBounty program.

If you need any assistance with the upgradation or require additional information, please write to us at support@datasecurityplus.com.

Email Download Link