A vulnerability identified as critical has been detected in MB Connect Line mbCONNECT24 and mymbCONNECT24 up to 2.20.0. This issue affects the function getAlarmProfiles. This manipulation causes sql injection.

This vulnerability is handled as CVE-2026-40817. The attack can be initiated remotely. There is not any exploit available.