PatchSiren

Bottinelli Informatica CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Bottinelli Informatica CVE published 2026-08-19

CVE-2026-51367

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T14:17:32.460Z and has not been modified since then. The affected product or component is Bottinelli Informatica Vedo Suite v.1.2.5, and the vulnerability class is related to sensitive information disclosure. The likely operational impact is unauthorized data access, and the source-confidence limi [truncated]

CRITICAL Bottinelli Informatica CVE published 2026-08-19

CVE-2026-51366

CVE-2026-51366 is a SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5. The vulnerability allows a remote attacker to execute arbitrary code via the api_vedo/chat endpoint and the utente_chat parameter. Organizations should prioritize immediate patching or mitigation to prevent potential remote code execution attacks. The CVSS score is 9.9, indicating critical severity. Affected orga [truncated]