Description
Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user-supplied input in a web application component. Crafted input can be executed as part of backend database queries. The issue is exploitable without authentication, significantly elevating the risk.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Any version before 8.14.9
Credits
Abdulrahman Nour, Mandiant
Abdulrahman Nour, Mandiant
References
www.explorance.com/products/blue
online-help.explorance.com/...rity-advisories-(january-2026)
online-help.explorance.com/...urity-advisory:-cve-2025-57793
github.com/...Disclosures/blob/master/2026/MNDT-2026-0002.md