PatchSiren cyber security CVE debrief
CVE-2026-6887 BorG Technology Corporation CVE debrief
A critical SQL injection vulnerability affects Borg SPM 2007, a sales performance management software developed by BorG Technology Corporation. The product reached end-of-life with sales discontinued in 2008, leaving no supported remediation path. The vulnerability allows unauthenticated remote attackers to execute arbitrary SQL commands with full database access—enabling unauthorized read, modification, and deletion of data. The CVSS 4.0 vector indicates network attack vector with low attack complexity, no privileges required, and high impact across confidentiality, integrity, and availability dimensions. Taiwanese CERT (TWCERT/CC) is the primary reporting source, with disclosure occurring in April 2026 and subsequent modification in May 2026. No known exploitation in ransomware campaigns has been documented.
- Vendor
- BorG Technology Corporation
- Product
- Borg SPM 2007
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-23
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-04-23
- Advisory updated
- 2026-05-19
Who should care
Organizations with legacy sales performance management infrastructure, particularly those in regions where Borg SPM 2007 was historically deployed; security teams managing end-of-life software inventories; compliance officers responsible for data protection in environments running unsupported applications
Technical summary
Borg SPM 2007 contains an unauthenticated SQL injection vulnerability (CWE-89) permitting arbitrary SQL command execution. The application fails to properly sanitize user-supplied input before constructing database queries. Attackers can exploit this without authentication credentials, enabling complete database compromise including data exfiltration, modification, and deletion. The product has been end-of-life since 2008 with no vendor support or security patches available.
Defensive priority
critical
Recommended defensive actions
- Immediately inventory all systems running Borg SPM 2007 to assess exposure
- Remove or isolate Borg SPM 2007 instances from production networks due to end-of-life status and unpatched critical vulnerability
- Implement network segmentation to restrict access to any remaining Borg SPM 2007 deployments
- Deploy web application firewall (WAF) rules to detect and block SQL injection patterns if immediate removal is not feasible
- Monitor database logs for anomalous query patterns indicative of exploitation
- Evaluate migration to supported sales performance management alternatives
- Document risk acceptance if temporary continued use is unavoidable, with executive sign-off
Evidence notes
Vulnerability disclosed by TWCERT/CC with official CVE assignment. Product vendor (BorG Technology Corporation) no longer supports the software. CVSS 4.0 scoring applied with critical severity rating. SQL injection classified under CWE-89.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-6887 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-6887
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-6887 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-6887
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.twcert.org.tw/en/cp-139-10863-2f48e-2.html
-
Source reference
Unverified legacy reference
URL: https://www.twcert.org.tw/tw/cp-132-10861-b8709-1.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.