🔐 CVE Alert

CVE-2026-6881

UNKNOWN 0.0

Authenticated SQL Injection Enables Unauthorized Access to Sensitive Information in Ellucian Advance Web and Legacy Advance

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field. This issue affects Advance Web: all versions; Legacy Advance: all versions. Ellucian CRM Advance is not impacted.

CWE CWE-89
Vendor ellucian
Product advance web
Published Jul 28, 2026
Stay Ahead of the Next One

Get instant alerts for ellucian advance web

Be the first to know when new unknown vulnerabilities affecting ellucian advance web are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Ellucian / Advance Web
0 ≤ *
Ellucian / Legacy Advance
0 ≤ *

References

NVD ↗ CVE.org ↗ EPSS Data ↗
labs.sra.io: https://labs.sra.io/posts/ellucian

Credits

Jeremy Slaven (SRA) Dylan Eliasson (SRA) Mark Blaho (SRA)