CVE-2026-14808 -- CVSS 9.8 Vulnerability Briefing
CVE-2026-14808 | CVSS 9.8 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-14808 is an unauthenticated sensitive information exposure vulnerability in the Prog Management System developed by PROG MIS, allowing remote attackers to access a restricted page and retrieve database account credentials without authentication.
Technical Detail
The flaw exists in a specific page within the Prog Management System that is accessible without any authentication controls, exposing database account information directly to unauthenticated remote requesters. An attacker can trigger this by sending a standard HTTP request to the affected endpoint, requiring no credentials, session tokens, or prior access. Successful exploitation yields database account details, which can be leveraged for direct database access, lateral movement, or full application compromise depending on the privilege level of the exposed credentials.
Exploitation Status
No known exploit code has been publicly observed or confirmed at this time. This vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. Despite the absence of confirmed exploitation, the low barrier to exploitation (unauthenticated, remotely triggerable) and the critical CVSS score of 9.8 warrant prompt remediation without waiting for active exploitation to be confirmed.
Who Is Targeting This
No specific threat actor attribution at this time. Neither confirmed nor reported threat actor activity has been associated with this CVE as of the date of this briefing.
What To Do
Apply any available vendor-supplied patch or update from PROG MIS immediately, prioritizing this as a critical-severity item given the unauthenticated remote access vector. If a patch is not yet available, restrict access to the affected page at the network perimeter using firewall rules or web application firewall policies to block unauthenticated external requests to the identified endpoint. Rotate any database credentials that may have been exposed, and audit database access logs for unauthorized connection attempts or queries originating from unexpected sources. Monitor vendor communications from PROG MIS for patch availability and apply updates as soon as they are released.