LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-39109

CVE-2026-39109 - Vulnerability Analysis

CriticalCVSS: 9.4

Last Updated: April 20, 2026

Apartment Visitors Management System - SQL Injection

Published: April 20, 2026Updated: April 20, 2026Remote Exploitable

Overview

Apartment Visitors Management System V1.1 contains a sql injection caused by unsanitized input in the username parameter of the login page (index.php), letting unauthenticated attackers retrieve sensitive database contents.

Severity & Score

Severity: Critical
CVSS Score: 9.4
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Unauthenticated attackers can retrieve sensitive database contents, potentially compromising the entire database.

Mitigation

Update to the latest version of Apartment Visitors Management System.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Apr 20, 2026

šŸ”“ CVE-2026-39109 - Critical (9.4) SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the username parameter of the login page (index.php). This allows an unauthenticated attacker to manipulate backend SQL queries du... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-39109/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Apr 20, 2026

šŸ”“ CVE-2026-39109 - Critical (9.4) SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the username parameter of the login page (index.php). This allows an unauthenticated attacker to manipulate backend SQL queries du... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-39109/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-39109
Severity
Critical
CVSS Score
9.4
Type
sql_injection
Status
rejected
EPSS
0.0%
Social Posts
2

CWE

  • CWE-89

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

EPSS Score

0.0%Probability of exploitation in the next 30 days