---
id: CVE-2026-6881
title: "A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive\_information from databases via a crafted SQL query in the class credit\_field.\n\n\n\nThis is…"
summary: "A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive\_information from databases via a crafted SQL query in the class credit\_field.\n\n\n\nThis is…"
severity: none
cwe:
  - CWE-89
published: '2026-07-28'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T15:52:04.827'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-6881'
references:
  - url: 'https://labs.sra.io/posts/ellucian'
    label: 57dba5dd-1a03-47f6-8b36-e84e47d335d8
tags:
  - nvd
epss: 0.00344
epssPercentile: 0.25345
ingestedAt: '2026-09-09T16:14:05.510Z'
---

## Overview

A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field.



This issue affects Advance Web: all versions; Legacy Advance: all versions.



Ellucian CRM Advance is not impacted.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
