STER software patched for SQLi, weak crypto flaws
Three vulnerabilities in STER software—SQL injection, weak password encoding, and plaintext transmission—allow authenticated attackers to access sensitive data; fixed in version 9.5.
CERT Polska coordinated disclosure of three vulnerabilities in STER software reported by Michelin CERT. CVE-2026-25606 is a SQL injection flaw affecting multiple search filters that allows authenticated attackers to access data belonging to other users or any data accessible to the application. CVE-2026-25607 involves use of a weak password encoding algorithm that enables attackers to reverse-engineer passwords by analyzing encoding patterns. CVE-2026-25608 concerns the transmission of data over unencrypted TCP connections, enabling man-in-the-middle attacks to intercept passwords, personal data, and authentication tokens.
All three vulnerabilities have been addressed in STER version 9.5. Organizations running affected versions should upgrade immediately to mitigate the risk of data exposure through SQL injection, credential compromise via weak cryptography, or interception of sensitive information in transit.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-25606
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free