EduAdmin Booking SQL Injection Risk Threatens Data Integrity for Institutions
A critical blind SQL injection flaw in EduAdmin Booking versions prior to 6.0.0 exposes organisations to severe data compromise risks, according to the National Vulnerability Database.

Key points
- The vulnerability is classified as critical with a CVSS score of 9.3 by the NVD.
- It affects all versions of MultiNet Interactive AB’s EduAdmin Booking before version 6.0.0.
- The flaw is a blind SQL injection, categorised under CWE-89 for improper neutralisation.
Organisations using MultiNet Interactive AB’s EduAdmin Booking software face significant security risks due to a critical vulnerability identified in the system. The National Vulnerability Database has assigned CVE-2026-96809 to this issue, rating it as critical with a CVSS score of 9.3. This high severity score indicates that the flaw allows for substantial exploitation potential, potentially compromising the integrity and confidentiality of sensitive institutional data stored within the booking platform.
How it unfolded
- The National Vulnerability Database published the record for CVE-2026-96809, identifying the specific weakness in the software.
- The vulnerability was categorised as CWE-89, highlighting improper neutralisation of special elements in SQL commands.
- The issue was determined to affect all iterations of EduAdmin Booking released prior to version 6.0.0.
Who is affected
Any institution or entity deploying EduAdmin Booking software prior to version 6.0.0 is affected by this vulnerability. The flaw resides in the core functionality of the application, allowing for blind SQL injection attacks. Because the vulnerability is rated as critical, the potential impact on affected organisations is severe. Attackers could potentially extract sensitive information, manipulate data, or bypass authentication mechanisms through this injection vector, putting user data and system integrity at risk.
The fix
Users must upgrade to version 6.0.0 or later to resolve this issue. The NVD record specifies that the vulnerability affects versions from n/a before 6.0.0. Consequently, any installation running a version lower than 6.0.0 remains exposed to the blind SQL injection attack. Organisations should verify their current version immediately and plan an upgrade path to ensure they are running a patched release. No alternative mitigations or temporary fixes have been confirmed by the vendor or the NVD at this time.
What to do and how to stay safe: EduAdmin Booking
- Audit your current EduAdmin Booking installation to determine if it is running a version prior to 6.0.0.
- Monitor network traffic for unusual database query patterns that may indicate blind SQL injection attempts.
- Restrict access to the booking application to authorised personnel only to reduce the attack surface.
- Review logs for any signs of unauthorised data access or manipulation once the vendor provides an update.
Step-by-step guide: Patch Management: Eight Questions Answered for Stability
General security guidance from the Malware Brief newsroom. It is not confirmed advice from the organisations named in this story.
Frequently asked questions
What is the CVSS score for CVE-2026-96809?
The CVSS score for CVE-2026-96809 is 9.3, which is classified as critical according to the National Vulnerability Database.
Which versions of EduAdmin Booking are affected by this vulnerability?
All versions of EduAdmin Booking prior to version 6.0.0 are affected by this blind SQL injection vulnerability.
What type of vulnerability is CVE-2026-96809?
CVE-2026-96809 is a blind SQL injection vulnerability, categorised under CWE-89 for improper neutralisation of special elements.



