AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T14:17:32.460Z and has not been modified since then. The affected product or component is Bottinelli Informatica Vedo Suite v.1.2.5, and the vulnerability class is related to sensitive information disclosure. The likely operational impact is unauthorized data access, and the source-confidence limi [truncated]
CRITICALBottinelli InformaticaCVE published 2026-08-19
CVE-2026-51366 is a SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5. The vulnerability allows a remote attacker to execute arbitrary code via the api_vedo/chat endpoint and the utente_chat parameter. Organizations should prioritize immediate patching or mitigation to prevent potential remote code execution attacks. The CVSS score is 9.9, indicating critical severity. Affected orga [truncated]