top of page
perceptive_background_267k.jpg

ELBA5 5.8.0 contains a remote code execution vulnerability that allows attackers to obtain database credentials and execute arbitrary commands with SYSTEM level…

Published:

21 April 2026 at 22:00:00

Alert date:

22 April 2026 at 22:11:22

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Database & Storage

CVE-2018-25272 affects ELBA5 version 5.8.0, allowing remote code execution with SYSTEM level privileges. Attackers can exploit default database connector credentials to decrypt DBA passwords and execute arbitrary commands. The vulnerability enables command execution through xp_cmdshell stored procedure or creation of backdoor users in the BEDIENER table. This represents a critical security flaw providing complete system compromise capabilities to remote attackers.

Technical details

Mitigation steps:

Affected products:

ELBA5

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page