A vulnerability marked as critical has been reported in Ellucian Advance Web and Legacy Advance. This issue affects some unknown processing of the component Giving Reports. Performing a manipulation of the argument credit results in sql injection.
This vulnerability was named CVE-2026-6881. The attack may be initiated remotely. There is no available exploit.