<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>CVE-2026-6881 on SRA Labs | Cybersecurity Research &amp; Innovation by Security Risk Advisors</title>
    <link>https://labs.sra.io/tags/cve-2026-6881/</link>
    <description>Recent content in CVE-2026-6881 on SRA Labs | Cybersecurity Research &amp; Innovation by Security Risk Advisors</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 28 Jul 2026 12:00:00 +0000</lastBuildDate><atom:link href="https://labs.sra.io/tags/cve-2026-6881/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Advisory: Ellucian Advance</title>
      <link>https://labs.sra.io/posts/ellucian/</link>
      <pubDate>Tue, 28 Jul 2026 12:00:00 +0000</pubDate>
      
      <guid>https://labs.sra.io/posts/ellucian/</guid>
      <description>&lt;h1 id=&#34;summary&#34;&gt;Summary&lt;/h1&gt;
&lt;p&gt;SRA has identified a SQL injection vulnerability in Ellucian Advance Web and Legacy Advance.&lt;/p&gt;
&lt;h1 id=&#34;cve-identifiers&#34;&gt;CVE Identifiers&lt;/h1&gt;
&lt;table&gt;
  &lt;thead&gt;
      &lt;tr&gt;
          &lt;th&gt;CVE ID&lt;/th&gt;
          &lt;th&gt;CVE Name&lt;/th&gt;
      &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
      &lt;tr&gt;
          &lt;td&gt;CVE-2026-6881&lt;/td&gt;
          &lt;td&gt;Authenticated SQL Injection Enables Unauthorized Access to Sensitive Information in Ellucian Advance Web and Legacy Advance&lt;/td&gt;
      &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;
&lt;h1 id=&#34;vulnerability-details--description&#34;&gt;Vulnerability Details / Description&lt;/h1&gt;
&lt;h2 id=&#34;cve-2026-6881-authenticated-sql-injection-enables-unauthorized-access-to-sensitive-information-in-ellucian-advance-web-and-legacy-advance&#34;&gt;CVE-2026-6881 Authenticated SQL Injection Enables Unauthorized Access to Sensitive Information in Ellucian Advance Web and Legacy Advance&lt;/h2&gt;
&lt;p&gt;A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field.&lt;/p&gt;</description>
      <content>&lt;h1 id=&#34;summary&#34;&gt;Summary&lt;/h1&gt;
&lt;p&gt;SRA has identified a SQL injection vulnerability in Ellucian Advance Web and Legacy Advance.&lt;/p&gt;
&lt;h1 id=&#34;cve-identifiers&#34;&gt;CVE Identifiers&lt;/h1&gt;
&lt;table&gt;
  &lt;thead&gt;
      &lt;tr&gt;
          &lt;th&gt;CVE ID&lt;/th&gt;
          &lt;th&gt;CVE Name&lt;/th&gt;
      &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
      &lt;tr&gt;
          &lt;td&gt;CVE-2026-6881&lt;/td&gt;
          &lt;td&gt;Authenticated SQL Injection Enables Unauthorized Access to Sensitive Information in Ellucian Advance Web and Legacy Advance&lt;/td&gt;
      &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;
&lt;h1 id=&#34;vulnerability-details--description&#34;&gt;Vulnerability Details / Description&lt;/h1&gt;
&lt;h2 id=&#34;cve-2026-6881-authenticated-sql-injection-enables-unauthorized-access-to-sensitive-information-in-ellucian-advance-web-and-legacy-advance&#34;&gt;CVE-2026-6881 Authenticated SQL Injection Enables Unauthorized Access to Sensitive Information in Ellucian Advance Web and Legacy Advance&lt;/h2&gt;
&lt;p&gt;A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Severity&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The CVSS severity level of this vulnerability has been calculated to be 9.4 (Critical)&lt;/p&gt;
&lt;p&gt;CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L&lt;/p&gt;
&lt;h1 id=&#34;affected-versions-and-models&#34;&gt;Affected Versions and Models&lt;/h1&gt;
&lt;p&gt;Affects all versions of Ellucian Advance Web before AWA-2022-ORA-17.&lt;/p&gt;
&lt;p&gt;Affects all versions of Ellucian Legacy Advance before AWA-2022-ORA-17.&lt;/p&gt;
&lt;p&gt;Ellucian CRM Advance is not impacted.&lt;/p&gt;
&lt;h1 id=&#34;mitre-cwe-weakness-enumeration&#34;&gt;MITRE CWE Weakness Enumeration&lt;/h1&gt;
&lt;p&gt;CWE-89 Improper neutralization of special elements used in an SQL command (&amp;lsquo;SQL injection&amp;rsquo;)&lt;/p&gt;
&lt;h1 id=&#34;remediation-options&#34;&gt;Remediation Options&lt;/h1&gt;
&lt;p&gt;Apply hotfix AWA-2022-ORA-17.&lt;/p&gt;
&lt;h1 id=&#34;source&#34;&gt;Source&lt;/h1&gt;
&lt;p&gt;These vulnerabilities were discovered by Jeremy Slaven, Dylan Eliasson, and Mark Blaho as part of research performed by Security Risk Advisors.&lt;/p&gt;
&lt;h1 id=&#34;timeframe&#34;&gt;Timeframe&lt;/h1&gt;
&lt;ul&gt;
&lt;li&gt;April 24, 2026 - SRA submits vulnerability to vendor&lt;/li&gt;
&lt;li&gt;May 15, 2026 - Vendor releases hotfix&lt;/li&gt;
&lt;li&gt;July 28, 2026 - SRA publishes CVEs and advisory&lt;/li&gt;
&lt;/ul&gt;
</content>
    </item>
    
  </channel>
</rss>
