CVE-2026-13337
Received Received - Intake

SQL Injection in NetBotz via Web-Service Interface

Vulnerability report for CVE-2026-13337, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: Schneider Electric SE

Description

CWE-564: SQL Injection: Hibernate vulnerability exists that could allow the injection of a malicious HQL query in the NetBotz database when a malicious user is logged into the NetBotz via the web-service interface or webui.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
schneider_electric netbotz to 5.6.0 (exc)
schneider_electric netbotz 5.6.0
schneider_electric netbotz From 5.5.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-564 Using Hibernate to execute a dynamic SQL statement built with user-controlled input can allow an attacker to modify the statement's meaning or to execute arbitrary SQL commands.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a medium-severity SQL injection vulnerability affecting Schneider Electric NetBotz 5 – 750/755 products running versions 5.5.2 and prior. It allows a malicious user logged into the NetBotz web interface or web-service to inject a harmful HQL query into the NetBotz database, potentially leading to unauthorized data access or manipulation.

Detection Guidance

Check NetBotz firmware version via GUI under 'About NetBotz' to confirm if it is 5.5.2 or earlier. Monitor web interface logs for unusual HQL query patterns or unauthorized database access attempts.

Impact Analysis

An attacker could exploit this vulnerability to access or manipulate sensitive data stored in the NetBotz database. This may include sensitive information such as user credentials, system configurations, or other confidential data, depending on the database contents.

Compliance Impact

This vulnerability could lead to unauthorized access or exposure of personal or sensitive data, which may violate compliance requirements under regulations like GDPR or HIPAA. Organizations using affected NetBotz products must address this issue to maintain compliance.

Mitigation Strategies

Upgrade NetBotz firmware to version 5.6.0 or later immediately. After installation, reboot the system to apply changes. Restrict web interface access to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13337. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart