{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-18630",
        "assignerOrgId": "ca940d4e-fea4-4aa2-9a58-591a58b1ce21",
        "state": "PUBLISHED",
        "assignerShortName": "TR-CERT",
        "dateReserved": "2026-08-03T09:24:46.122Z",
        "datePublished": "2026-09-01T15:08:50.285Z",
        "dateUpdated": "2026-09-01T15:21:49.187Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "ca940d4e-fea4-4aa2-9a58-591a58b1ce21",
                "shortName": "TR-CERT",
                "dateUpdated": "2026-09-01T15:08:50.285Z"
            },
            "title": "SQL Injection in TMT Machine's Talassoft Industrial Management Software",
            "datePublic": "2026-09-01T15:06:00.000Z",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-89",
                            "description": "CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection')",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-66",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-66 SQL Injection"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "TMT Machine Industry and Trade Ltd. Co.",
                    "product": "Talassoft Industrial Management Software",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "V.4",
                            "lessThan": "V.16",
                            "versionType": "custom"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows SQL Injection.\n\nThis issue affects Talassoft Industrial Management Software: from V.4 before V.16.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows SQL Injection.<p>This issue affects Talassoft Industrial Management Software: from V.4 before V.16.</p>"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0965",
                    "tags": [
                        "government-resource"
                    ]
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV3_1": {
                        "version": "3.1",
                        "attackVector": "NETWORK",
                        "attackComplexity": "LOW",
                        "privilegesRequired": "LOW",
                        "userInteraction": "NONE",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "HIGH",
                        "availabilityImpact": "HIGH",
                        "baseSeverity": "HIGH",
                        "baseScore": 8.8,
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
                    }
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Efe Özel",
                    "type": "finder"
                },
                {
                    "lang": "en",
                    "value": "Cemil Sefa Özcan",
                    "type": "analyst"
                },
                {
                    "lang": "en",
                    "value": "FORDEFENCE",
                    "type": "sponsor"
                }
            ],
            "source": {
                "defect": [
                    "TR-26-0965"
                ],
                "advisory": "TR-26-0965",
                "discovery": "UNKNOWN"
            },
            "x_generator": {
                "engine": "Vulnogram 1.0.5"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-09-01T15:21:34.762413Z",
                                "id": "CVE-2026-18630",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-09-01T15:21:49.187Z"
                }
            }
        ]
    }
}