


Perceptive Security
SOC/SIEM Consultancy

Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inj…
Published:
22 April 2026 at 22:00:00
Alert date:
23 April 2026 at 11:02:17
Source:
nvd.nist.gov
Enterprise Applications, Database & Storage
CVE-2026-6887 affects Borg SPM 2007, a sales management system developed by BorG Technology Corporation (sales ended in 2008). The vulnerability allows unauthenticated remote attackers to perform SQL injection attacks, enabling them to inject arbitrary SQL commands into the database. Attackers can exploit this vulnerability to read sensitive data from the database, modify existing records, or delete database contents entirely. Despite the product being discontinued, systems may still be in use and vulnerable to attack. The vulnerability poses significant risk due to the lack of authentication requirements and the potential for complete database compromise.
Technical details
Mitigation steps:
Affected products:
Borg SPM 2007
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-6887
https://www.twcert.org.tw/en/cp-139-10863-2f48e-2.html
https://www.twcert.org.tw/tw/cp-132-10861-b8709-1.html
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
