{"id":"CVE-2026-44923","title":"SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to escalate privileges.","summary":"SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to escalate privileges.","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","cwe":["CWE-89"],"vendor":"veritas","product":"infoscale_operations_manager","affected":["infoscale_operations_manager < 9.1.3"],"patched":["infoscale_operations_manager 9.1.3"],"published":"2026-05-20","updated":"2026-07-23","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-44923","references":[{"url":"https://supportinfoscale.cloud.com/support-home/kbsearch/article?articleNumber=1000766080&articleTitle=InfoScale_Operations_Manager_IOM_web_application_Security_Bulletin_for_CVE_2026_44923_CVE_2026_44924_and_CVE_2026_44925","label":"cve@mitre.org"},{"url":"https://www.veritas.com/support/en_US/doc/120571566-166757640-0/viom_tot_v118836641-166757640","label":"cve@mitre.org"}],"tags":["nvd"],"epss":0.00309,"epssPercentile":0.23825,"ingestedAt":"2026-07-23T12:17:55.365Z","slug":"CVE-2026-44923","body":"## Overview\n\nSQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to escalate privileges.\n\n## Affected\n\n- `infoscale_operations_manager < 9.1.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `infoscale_operations_manager 9.1.3`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}