


Perceptive Security
SOC/SIEM Consultancy

ELBA5 5.8.0 contains a remote code execution vulnerability that allows attackers to obtain database credentials and execute arbitrary commands with SYSTEM level…
Published:
21 April 2026 at 22:00:00
Alert date:
22 April 2026 at 22:11:22
Source:
nvd.nist.gov
Enterprise Applications, Database & Storage
CVE-2018-25272 affects ELBA5 version 5.8.0, allowing remote code execution with SYSTEM level privileges. Attackers can exploit default database connector credentials to decrypt DBA passwords and execute arbitrary commands. The vulnerability enables command execution through xp_cmdshell stored procedure or creation of backdoor users in the BEDIENER table. This represents a critical security flaw providing complete system compromise capabilities to remote attackers.
Technical details
Mitigation steps:
Affected products:
ELBA5
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2018-25272
https://www.elba.at
https://www.exploit-db.com/exploits/45905
https://www.vulncheck.com/advisories/elba5-remote-code-execution-via-database-access
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
