Critical· 9.8official fix available
CVE-2026-7188
A SQL injection flaw exists in Armiya Information Technologies Ltd. Co.'s Access Control System in versions before 2. Attackers can run arbitrary SQL commands, potentially gaining full control of the system.
publishedSep 10, 2026
last modifiedSep 10, 2026
sourcesNVD
severity · cvss
9.8
critical · how bad it is
exploitation · epss
<1%
25th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Oct 10, 2026
An official fix is available, so this entry is kept for 30 days and then removed automatically.
01
Who is affected
Armiya Information Technologies Ltd. Co. Access Control System, versions before 2.
02
Real-world impact
An attacker could read, modify, or delete data, or take full control of the system.
03
Why this severity
The CVSS score of 9.8 reflects that the flaw can be exploited remotely without authentication, allowing attackers to fully compromise confidentiality, integrity, and availability.
04
What to do about it
official fix available
recommended steps
- 01Upgrade to Access Control System version 2 or later.
NVD description
05
Timeline
- Sep 10, 2026 · 5d agoPublishedDisclosed and added to the National Vulnerability Database.
- Sep 10, 2026 · 5d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
06
How it’s attacked
Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07
References & advisories
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →