---
id: CVE-2026-18782
title: >-
  Improper neutralization of special elements used in an SQL command ('SQL
  injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc
summary: >-
  Improper neutralization of special elements used in an SQL command ('SQL
  injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc.
  Trex MES allows Command Line Execution through SQL Injection.


  This issue affects Trex ME…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-89
vendor: Trex Digital Smart Manufacturing Systems Inc.
product: Trex MES
affected:
  - trex_mes <= 2026-09-29
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T16:18:57.403'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18782'
references:
  - url: 'https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1225'
    label: iletisim@usom.gov.tr
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-30T14:56:23.205678Z'
ingestedAt: '2026-09-30T15:07:05.388Z'
---

## Overview

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection.

This issue affects Trex MES: through 2026-09-29.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
