A vulnerability, which was classified as critical, was found in MB Connect Line mbCONNECT24 and mymbCONNECT24 up to 2.20.0. This impacts the function getComponentScalings. Such manipulation leads to sql injection.

This vulnerability is referenced as CVE-2026-40839. It is possible to launch the attack remotely. No exploit is available.