---
id: CVE-2026-18198
title: >-
  Improper neutralization of special elements used in an SQL command ('SQL
  injection') vulnerability in TAC Information Services Internal and External
  Trade Inc
summary: >-
  Improper neutralization of special elements used in an SQL command ('SQL
  injection') vulnerability in TAC Information Services Internal and External
  Trade Inc. GOLDENHORN ONEIT allows Blind SQL Injection.


  This issue affects GOLDENHORN O…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-89
published: '2026-09-04'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T14:12:48.213'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18198'
references:
  - url: 'https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0990'
    label: iletisim@usom.gov.tr
tags:
  - nvd
epss: 0.00244
epssPercentile: 0.13909
ingestedAt: '2026-09-08T15:33:26.960Z'
---

## Overview

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TAC Information Services Internal and External Trade Inc. GOLDENHORN ONEIT allows Blind SQL Injection.

This issue affects GOLDENHORN ONEIT: before Göbeklitepe.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
