top of page
perceptive_background_267k.jpg

ELBA5 5.8.0 contains a remote code execution vulnerability that allows attackers to obtain database credentials and execute arbitrary commands with SYSTEM level…

Published:

21 april 2026 om 22:00:00

Alert date:

22 april 2026 om 17:03:04

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Database & Storage

ELBA5 version 5.8.0 contains a critical remote code execution vulnerability that enables attackers to compromise database security and execute arbitrary commands with SYSTEM-level privileges. The vulnerability stems from default connector credentials that allow unauthorized database access. Attackers can decrypt the database administrator password and leverage the xp_cmdshell stored procedure to execute system commands. Additionally, threat actors can establish persistence by adding backdoor users to the BEDIENER table. This vulnerability provides complete system compromise through database exploitation.

Technical details

Mitigation steps:

Affected products:

ELBA5

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page