CVE-2026-6881
Authenticated SQL Injection Enables Unauthorized Access to Sensitive Information in Ellucian Advance Web and Legacy Advance
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field. This issue affects Advance Web: all versions; Legacy Advance: all versions. Ellucian CRM Advance is not impacted.
| CWE | CWE-89 |
| Vendor | ellucian |
| Product | advance web |
| Published | Jul 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for ellucian advance web
Be the first to know when new unknown vulnerabilities affecting ellucian advance web are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Ellucian / Advance Web
0 ≤ *
Ellucian / Legacy Advance
0 ≤ *
Credits
Jeremy Slaven (SRA) Dylan Eliasson (SRA) Mark Blaho (SRA)