CVE-2026-40529
MEDIUM
NVD
CVSS Score
4.7
Severity
MEDIUM
Published
Apr 23, 2026
Vendor
unknown
Description
CMS ALAYA provided by KANATA Limited contains an SQL injection vulnerability. Information stored in the database may be obtained or altered by an attacker with access to the administrative interface.