CVE-2026-40522 HIGH

CVE-2026-40522: FrontAccounting < 2.4.20 SQL Injection via rep601.php

Vendor Frontaccounting
Product FrontAccounting
Weakness CWE-89 · SQLi
Published June 29, 2026
Last update June 29, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Bank Statement report handler that allows authenticated attackers to extract arbitrary database data by injecting UNION SELECT payloads into the PARAM_0 POST parameter. Attackers can supply malicious SQL syntax through the unparameterized WHERE clause to retrieve sensitive information including usernames, password hashes, and email addresses from the users table, rendered into PDF report output.

Key dates

02Disclosure timeline

June 29, 2026 CVE published
June 29, 2026 Record updated