A critical SQL injection vulnerability, tracked as CVE-2026-16462, has been identified in Weidmueller's PROCON-WEB SCADA software, scoring 9.8 on the CVSS scale. This flaw allows remote, unauthenticated attackers to execute arbitrary SQL commands via an insecure 'GetGridData' endpoint. Affected versions include PROCON-WEB SCADA 1.0.0 to 6.11.2, with the need for immediate patching to version 6.11.3 as there is no confirmed exploitation reported yet.
The potential impact includes unauthorized data access, modification, or deletion, which could disrupt physical processes in industrial and building automation.