CRITICAL
Brainformatik
CVE published 2026-08-17
CVE-2026-50769
A SQL Injection vulnerability exists in the CRM+ application before and including version 2025.6 from Brainformatik. The vulnerability is located in the check conflict endpoint, which is used to check for conflicts in user calendars. This endpoint is vulnerable to SQL injection, allowing an attacker to execute arbitrary code. The vulnerability has a CVSS score of 9.8 and is considered critical. Defenders [truncated]