CVE-2026-55721 Details
Description
Storage Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl and debug.pl scripts. The cookie value is incorporated directly into database queries without adequate sanitization, allowing an unauthenticated remote attacker to manipulate those queries and extract sensitive information from the underlying database, including session tokens, password hashes, and stored secret keys.
A SQL injection vulnerability has been identified in StoneFly Storage Concentrator (both SC and SCVM) versions prior to 8.0.4.22. The issue arises in the login.pl and debug.pl scripts, where cookie values are processed and directly incorporated into database queries without proper sanitization. This flaw allows an unauthenticated remote attacker to manipulate the queries and extract sensitive information from the database, including session tokens, password hashes, and stored secret keys.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 30, 2026CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| StoneFly Storage Concentrator | < 8.0.4.22 < 8.0.4.26 < 8.0.4.29 |
CPE
Remediation
| |
| StoneFly Storage Concentrator Virtual Machine | < 8.0.4.22 < 8.0.4.26 < 8.0.4.29 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | New CVE Received | [email protected] |
Volerion