PatchSiren cyber security CVE debrief
CVE-2025-9953 DATABASE Software Training Consulting Ltd. CVE debrief
CVE-2025-9953 is a critical vulnerability in DATABASE Software Training Consulting Ltd.'s Databank Accreditation Software, allowing for SQL injection attacks. The vulnerability has a CVSS score of 9.8 and was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2025-9953). The affected software version is through 19022026. The vendor did not respond to early disclosure. For more information, see [resourceLinkAnnotations](https://nvd.nist.gov/vuln/detail/CVE-2025-9953).
- Vendor
- DATABASE Software Training Consulting Ltd.
- Product
- Databank Accreditation Software
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-19
- Original CVE updated
- 2026-06-25
- Advisory published
- 2026-02-19
- Advisory updated
- 2026-06-25
Who should care
Users of Databank Accreditation Software through version 19022026 should prioritize patching this vulnerability to prevent potential SQL injection attacks.
Technical summary
CVE-2025-9953 is an Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in Databank Accreditation Software. This issue allows attackers to inject SQL, potentially leading to unauthorized data access or modification. The vulnerability's CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a high severity.
Defensive priority
High
Recommended defensive actions
- Apply patches or updates provided by the vendor to address the vulnerability.
- Implement additional security measures, such as input validation and sanitization, to prevent SQL injection attacks.
- Monitor systems for suspicious activity and review logs regularly.
Evidence notes
The CVE record [cve-org](https://www.cve.org/CVERecord?id=CVE-2025-9953) and NVD detail [nvd](https://nvd.nist.gov/vuln/detail/CVE-2025-9953) provide further information on this vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-9953 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-9953
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-9953 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-9953
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0078
-
Source reference
Unverified legacy reference
URL: https://www.usom.gov.tr/bildirim/tr-26-0078
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.