Sceawere

Vulnerability Detail

CVE-2026-86595UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in Iron Mountain EnVision

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
3h ago
Vendor
Iron Mountain Archiving Services Inc.
Product
enVision
Attack Type
CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows SQL Injection. This issue affects enVision: before 260655.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-09-28T14:17:21.030Z",
  "pubdate": "2026-09-28T14:17:21.030Z",
  "executiveSummary": "The Iron Mountain EnVision archiving platform is susceptible to an SQL Injection (SQLi) vulnerability, classified as an Improper Neutralization of Special Elements used in an SQL Command. This security flaw enables unauthorized attackers to manipulate backend database queries through the injection of malicious SQL syntax. Successful exploitation allows for the unauthorized extraction, modification, or deletion of sensitive archived data, potentially leading to a complete compromise of the database management system. This issue affects all versions of EnVision prior to 260655. The vulnerability poses a critical risk to data confidentiality, integrity, and availability within the archiving environment. Attackers can leverage this flaw to bypass authentication mechanisms or retrieve sensitive records without requiring elevated privileges if the vulnerable interface is accessible over the network. Remediation requires an immediate update to the latest provided patch level to sanitize user-supplied inputs and prevent the execution of arbitrary SQL commands.",
  "technicalDetails": "The vulnerability originates from the failure of the EnVision application to properly sanitize and validate user-supplied input before incorporating it into dynamic SQL query constructions. This flaw permits an attacker to escape the intended data context and inject arbitrary SQL commands into the backend database engine. The underlying root cause is the reliance on insecure query concatenation or insufficiently parameterized database calls within the application's request-handling layer.\nExploitation occurs when an attacker identifies an entry point, such as a URL parameter, HTTP header, or form field, that interfaces directly with the backend database. By supplying crafted SQL tokens (e.g., `' OR 1=1 --`), the attacker can alter the query logic. For instance, an input designed to force a conditional truth in a 'WHERE' clause could allow the attacker to bypass authentication or extract unauthorized records from the database tables.\nThe attack flow typically follows a reconnaissance phase where the attacker probes inputs to confirm syntax errors or timing-based responses, followed by the deployment of structured payloads. Depending on the database configuration, an attacker may leverage techniques such as UNION-based SQL injection to append unauthorized query results to legitimate output, or boolean/error-based blind SQL injection to infer data byte-by-byte. If the database user account possesses excessive permissions, the attacker might perform administrative operations, including the dropping of tables or the exfiltration of the entire database schema.\nThis vulnerability exists within the EnVision application components responsible for data retrieval and reporting. Affected versions include all iterations prior to 260655. The threat is particularly significant for network-exposed instances where the application is accessible to untrusted users. Post-exploitation impact is severe, as it facilitates unauthorized data disclosure, lateral movement within the network if the database environment is linked to other systems, and the total loss of integrity for the archive repository managed by the EnVision platform."
}
CVE-2026-86595: SQL Injection in Iron Mountain EnVision (HIGH Severity, CVSS: 8.8) | Sceawere