CVE Feed

    Dashboard / CVE / CVE-2026-10731

    CVE-2026-10731

    SQL injection in the ‘two_steps_auth_code’ parameter processed by the ‘twoStepsAuthVerification’ function within the ‘/user-login’ endpoint. The two-factor authentication (2FA) functionality can be accessed without prior authentication, allowing unauthenticated attackers to execute arbitrary SQL queries on the backend database. A successful exploit could lead to database enumeration, the unauthorised creation of privileged users, the modification or deletion of critical information, and denial-of-service conditions.

    Published:Jun 9, 2026
    Last Modified:Jun 9, 2026
    EPS:Jun 9, 2026
    EPSS Score:0.00112
    CVSS Score:9.3

    Affected Products

    Vendor
    Nemon
    Product
    Nemon Trade Energy
    Vendor
    Nemon
    Product
    Nemon Trade Energy Crm

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High