Cyber Posture

CVE-2026-41460

CriticalPublic PoC

Published: 23 April 2026

Published
23 April 2026
Modified
29 April 2026
KEV Added
Patch
CVSS Score 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0042 62.2th percentile
Risk Priority 20 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2026-41460 is a critical-severity SQL Injection (CWE-89) vulnerability in Socialengine Socialengine. Its CVSS base score is 9.8 (Critical).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked in the top 37.8% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

The strongest mitigations our analysis identified are NIST 800-53 SI-10 (Information Input Validation) and SI-2 (Flaw Remediation).

Threat & Defense at a Glance

What attackers do: exploitation maps to Exploit Public-Facing Application (T1190) and 1 other technique. What defenders deploy: see the NIST 800-53 controls recommended below.
Threat & Defense Details

Mitigating Controls (NIST 800-53 r5)AI

prevent

Directly prevents SQL injection by requiring validation and sanitization of user-supplied input like the text parameter before incorporation into SQL queries.

prevent

Ensures timely remediation of the specific SQL injection flaw in the /activity/index/get-memberall endpoint through patching and testing.

detect

Vulnerability scanning identifies SQL injection vulnerabilities such as CVE-2026-41460 in the application, enabling proactive remediation.

MITRE ATT&CK Enterprise TechniquesAI

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
T1213.006 Databases Collection
Adversaries may leverage databases to mine valuable information.
Why these techniques?

SQL injection in public-facing SocialEngine web application directly enables T1190 (Exploit Public-Facing Application) for unauthenticated remote access; facilitates arbitrary database reads via T1213.006 (Databases), supporting data exfiltration and password resets.

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

NVD Description

SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoint where user-supplied input passed via the text parameter is not sanitized before being incorporated into a SQL query. An unauthenticated remote attacker can exploit this vulnerability…

more

to read arbitrary data from the database, reset administrator account passwords, and gain unauthorized access to the Packages Manager in the Admin Panel, potentially enabling remote code execution.

Deeper analysisAI

CVE-2026-41460 is a SQL injection vulnerability (CWE-89) affecting SocialEngine versions 7.8.0 and prior. The flaw resides in the /activity/index/get-memberall endpoint, where user-supplied input via the text parameter is not sanitized before being incorporated into a SQL query. Published on 2026-04-23, it carries a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating critical severity due to its high impact on confidentiality, integrity, and availability.

An unauthenticated remote attacker can exploit this vulnerability over the network with low complexity. Successful exploitation allows reading arbitrary data from the database, resetting administrator account passwords, and gaining unauthorized access to the Packages Manager in the Admin Panel, which can potentially lead to remote code execution.

Advisories detailing the vulnerability and mitigation strategies are available from sources including Karma Insecurity (KIS-2026-08 at https://karmainsecurity.com/KIS-2026-08), VulnCheck (https://www.vulncheck.com/advisories/socialengine-sql-injection-via-activity-index-get-memberall), Full Disclosure (http://seclists.org/fulldisclosure/2026/Apr/12), and the vendor site (https://socialengine.com). Security practitioners should consult these references for patch information and remediation guidance.

Details

CWE(s)

Affected Products

socialengine
socialengine
≤ 7.8.0

CVEs Like This One

CVE-2026-41461Same product: Socialengine Socialengine
CVE-2025-40639Shared CWE-89
CVE-2019-25674Shared CWE-89
CVE-2019-25526Shared CWE-89
CVE-2019-25524Shared CWE-89
CVE-2025-23780Shared CWE-89
CVE-2026-40887Shared CWE-89
CVE-2024-51818Shared CWE-89
CVE-2026-31891Shared CWE-89
CVE-2026-30951Shared CWE-89

References