Improper access control in Emlog Pro - CVE-2026-73850

 

Improper access control in Emlog Pro - CVE-2026-73850

Published: August 15, 2026


Vulnerability identifier: #VU142820
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-73850
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary SQL commands.

The vulnerability exists due to improper access control in the queryDatabase() function in admin/ai.php when handling execute_tool requests for the query_database tool. A remote privileged user can send a specially crafted POST request containing arbitrary SQL statements to execute arbitrary SQL commands.

The issue affects the admin functionality exposed through the ai.php endpoint.


Affected software

Emlog Pro

How to mitigate CVE-2026-73850

Install security update from vendor's website.

Emlog Pro - update to 2.6.21

External References

Related Security Bulletins