Pixa Bank 2.0 was disclosed with a high-severity unauthenticated SQL injection vulnerability, tracked as CVE-2026-49491, in the agence-ajax.php API. The flaw affects the rib parameter and can be triggered with crafted POST requests, allowing attackers to perform UNION-based SQL injection against the backend database without logging in.
Successful exploitation can expose sensitive records including user names, email addresses, and phone numbers. The issue was classified as CWE-89 and assigned a CVSS v3.1 score vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N, reflecting low attack complexity and high confidentiality impact, with references published by VulnCheck and other security tracking sources.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
VulnCheck published an advisory describing an unauthenticated SQL injection vulnerability in Pixa Bank 2.0 via the agence-ajax.php API. The issue allows UNION-based SQL injection through the 'rib' parameter and may expose names, email addresses, and phone numbers.
The CVE record for an unauthenticated SQL injection in Pixa Bank 2.0 states it was received by disclosure@vulncheck.com. The flaw affects the 'rib' parameter in POST requests to agence-ajax.php and can expose sensitive database contents.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.