{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-55721","assignerOrgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","state":"PUBLISHED","assignerShortName":"icscert","dateReserved":"2026-06-22T20:13:36.520Z","datePublished":"2026-06-30T22:36:22.639Z","dateUpdated":"2026-07-01T15:35:19.478Z"},"containers":{"cna":{"providerMetadata":{"orgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","shortName":"icscert","dateUpdated":"2026-06-30T22:36:22.639Z"},"title":"SQL Injection in StoneFly Storage Concentrator","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-89","description":"CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection')","type":"CWE"}]}],"affected":[{"vendor":"StoneFly","product":"Storage Concentrator","versions":[{"status":"affected","version":"0","lessThan":"8.0.4.22","versionType":"custom"},{"status":"unaffected","version":"8.0.4.29"}],"defaultStatus":"unaffected"},{"vendor":"StoneFly","product":"Storage Concentrator Virtual Machine","versions":[{"status":"affected","version":"0","lessThan":"8.0.4.22","versionType":"custom"},{"status":"unaffected","version":"8.0.4.29"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"Storage Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl and debug.pl scripts. The cookie value is incorporated directly into database queries without adequate sanitization, allowing an unauthenticated remote attacker to manipulate those queries and extract sensitive information from the underlying database, including session tokens, password hashes, and stored secret keys.","supportingMedia":[{"type":"text/html","base64":false,"value":"Storage Concentrator (SC &amp; SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl and debug.pl scripts. The cookie value is incorporated directly into database queries without adequate sanitization, allowing an unauthenticated remote attacker to manipulate those queries and extract sensitive information from the underlying database, including session tokens, password hashes, and stored secret keys.&nbsp;<br>"}]}],"references":[{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-06"},{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-181-06.json"},{"url":"https://stonefly.com/contact-us/"}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","subConfidentialityImpact":"HIGH","vulnIntegrityImpact":"LOW","subIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"CRITICAL","baseScore":9.2,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N"}},{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE","baseSeverity":"CRITICAL","baseScore":9.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N"}}],"solutions":[{"lang":"en","value":"StoneFly recommends that users upgrade to Storage Concentrator version 8.0.4.29 or later to remediate these vulnerabilities.","supportingMedia":[{"type":"text/html","base64":false,"value":"StoneFly recommends that users upgrade to Storage Concentrator version 8.0.4.29 or later to remediate these vulnerabilities."}]},{"lang":"en","value":"For additional questions or support, users may contact StoneFly at  https://stonefly.com/contact-us/","supportingMedia":[{"type":"text/html","base64":false,"value":"<span>For additional questions or support, users may contact StoneFly at&nbsp;</span><a href=\"https://stonefly.com/contact-us/\">https://stonefly.com/contact-us/</a>"}]}],"credits":[{"lang":"en","value":"David Yesland of Rhino Security Labs reported this vulnerability to CISA.","type":"reporter"}],"source":{"advisory":"ICSA-26-181-06","discovery":"EXTERNAL"},"x_generator":{"engine":"Vulnogram 1.0.2"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-07-01T15:35:12.509357Z","id":"CVE-2026-55721","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-07-01T15:35:19.478Z"}}]}}