Summary

SRA has identified a SQL injection vulnerability in Ellucian Advance Web and Legacy Advance.

CVE Identifiers

CVE ID CVE Name
CVE-2026-6881 Authenticated SQL Injection Enables Unauthorized Access to Sensitive Information in Ellucian Advance Web and Legacy Advance

Vulnerability Details / Description

CVE-2026-6881 Authenticated SQL Injection Enables Unauthorized Access to Sensitive Information in Ellucian Advance Web and Legacy Advance

A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field.

Severity

The CVSS severity level of this vulnerability has been calculated to be 9.4 (Critical)

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L

Affected Versions and Models

Affects all versions of Ellucian Advance Web before AWA-2022-ORA-17.

Affects all versions of Ellucian Legacy Advance before AWA-2022-ORA-17.

Ellucian CRM Advance is not impacted.

MITRE CWE Weakness Enumeration

CWE-89 Improper neutralization of special elements used in an SQL command (‘SQL injection’)

Remediation Options

Apply hotfix AWA-2022-ORA-17.

Source

These vulnerabilities were discovered by Jeremy Slaven, Dylan Eliasson, and Mark Blaho as part of research performed by Security Risk Advisors.

Timeframe

  • April 24, 2026 - SRA submits vulnerability to vendor
  • May 15, 2026 - Vendor releases hotfix
  • July 28, 2026 - SRA publishes CVEs and advisory