Threat intelligence dashboard
CVE-2026-86595high

SQLi in Iron Mountain's enVision

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows SQL Injection. This issue affects enVision: before 260655.

Risk score

8.8

CVSS 3.1

Vendor
Iron Mountain Archiving Services Inc.
Product
enVision
CWE
CWE-89
Published
Sep 28, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

enVision

Iron Mountain Archiving Services Inc.

Version / rangeStatusType
0 to before 260655affectedcustom

Technical metrics

8.8

CVSS 3.1

Severity
high
Source
TR-CERT
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H