CVE-2026-13337

Summary

CWE-564: SQL Injection: Hibernate vulnerability exists that could allow the injection of a malicious HQL query in the NetBotz database when a malicious user is logged into the NetBotz via the web-service interface or webui.

Affected Software

VendorProductVersion RangeStatus
Schneider ElectricNetBotz 5 - 750/755Versions 5.5.2 and prioraffected

Weaknesses

  • CWE-564: CWE-564 SQL injection: hibernate

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References