CVE-2026-7486
This vulnerability is an SQL injection flaw in Netcad Software Inc.'s E-İmar product. It allows attackers to execute arbitrary SQL commands by injecting malicious input. The flaw is present in versions 2.10.1.0 up to, but not including, 3.0.2.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Netcad Software Inc. E-İmar, versions 2.10.1.0 through 3.0.1 (any version before 3.0.2).
Real-world impact
An attacker could read, modify, or delete data in the database, potentially compromising sensitive information, disrupting services, or gaining full control over the system.
Why this severity
The CVSS score of 9.8 reflects the vulnerability's high impact: it can be exploited remotely without authentication or user interaction, giving attackers full control over the database and the application.
What to do about it
- 01Upgrade E-İmar to version 3.0.2 or later.
- 02Restart the application to apply the update.
NVD-referenced vendor advisory
Timeline
- Jun 9, 2026 · Jun 9, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
- Jul 24, 2026 · 11d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.