---
id: CVE-2026-7188
title: >-
  Improper neutralization of special elements used in an SQL command ('SQL
  injection') vulnerability in Armiya Information Technologies Ltd
summary: >-
  Improper neutralization of special elements used in an SQL command ('SQL
  injection') vulnerability in Armiya Information Technologies Ltd. Co. Access
  Control System allows SQL Injection.


  This issue affects Access Control System: before …
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-89
vendor: Armiya Information Technologies Ltd. Co.
product: Access Control System
affected:
  - access_control_system < Versiyon 2
published: '2026-09-10'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:13:07.090'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-7188'
references:
  - url: 'https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1061'
    label: iletisim@usom.gov.tr
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-10T12:44:04.433078Z'
ingestedAt: '2026-09-10T08:44:05.578Z'
epss: 0.00468
epssPercentile: 0.37913
---

## Overview

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows SQL Injection.

This issue affects Access Control System: before Versiyon 2.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
