PatchSiren

Brainformatik CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Brainformatik CVE published 2026-08-17

CVE-2026-50769

A SQL Injection vulnerability exists in the CRM+ application before and including version 2025.6 from Brainformatik. The vulnerability is located in the check conflict endpoint, which is used to check for conflicts in user calendars. This endpoint is vulnerable to SQL injection, allowing an attacker to execute arbitrary code. The vulnerability has a CVSS score of 9.8 and is considered critical. Defenders [truncated]