CVE-2026-6887 CRITICAL

CVE-2026-6887: BorG Technology Corporation|Borg SPM 2007 - SQL Injection

Vendor Borg Technology Corporation
Product Borg SPM 2007
Weakness CWE-89 · SQLi
Published April 23, 2026
Last update April 23, 2026

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

Key dates

02Disclosure timeline

April 23, 2026 CVE published
April 23, 2026 Record updated