Advisory: Ellucian Advance
Summary⌗
SRA has identified a SQL injection vulnerability in Ellucian Advance Web and Legacy Advance.
CVE Identifiers⌗
| CVE ID | CVE Name |
|---|---|
| CVE-2026-6881 | Authenticated SQL Injection Enables Unauthorized Access to Sensitive Information in Ellucian Advance Web and Legacy Advance |
Vulnerability Details / Description⌗
CVE-2026-6881 Authenticated SQL Injection Enables Unauthorized Access to Sensitive Information in Ellucian Advance Web and Legacy Advance⌗
A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field.
Severity
The CVSS severity level of this vulnerability has been calculated to be 9.4 (Critical)
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L
Affected Versions and Models⌗
Affects all versions of Ellucian Advance Web before AWA-2022-ORA-17.
Affects all versions of Ellucian Legacy Advance before AWA-2022-ORA-17.
Ellucian CRM Advance is not impacted.
MITRE CWE Weakness Enumeration⌗
CWE-89 Improper neutralization of special elements used in an SQL command (‘SQL injection’)
Remediation Options⌗
Apply hotfix AWA-2022-ORA-17.
Source⌗
These vulnerabilities were discovered by Jeremy Slaven, Dylan Eliasson, and Mark Blaho as part of research performed by Security Risk Advisors.
Timeframe⌗
- April 24, 2026 - SRA submits vulnerability to vendor
- May 15, 2026 - Vendor releases hotfix
- July 28, 2026 - SRA publishes CVEs and advisory