CVE-2026-55740 Security Alert: CRITICAL Vulnerability
Urgent: CVE-2026-55740 requires immediate attention.
· 6 min read
Executive Summary
CVE-2026-55740 is a critical unauthenticated SQL injection in Nur-Alam39 bus-ticket (latest known commit: 459cabdbeb99c00225b26e46e3c2c30ae1de7bad). A remote attacker can send a crafted busid value to bus_info.php and read arbitrary data from the bus_service database. The issue is especially dangerous because the app appears to connect as root with an empty password, which can turn a simple data leak into full database compromise.
There are no released safe versions listed yet. If you run this code in production, treat it as exposed until you have patched the query, restricted database privileges, or removed the vulnerable component.
Immediate Action
- Take the endpoint offline or isolate it now if it is internet-facing. Put the app behind maintenance mode, a firewall rule, or temporary reverse-proxy block.
- Patch the SQL query immediately to use parameterized statements in
bus_info.php. Do not rely on escaping alone. - Stop using MySQL root for the application. Create a least-privilege account limited to only the tables and queries the app needs.
- Check logs for suspicious POSTs to
bus_info.php, especially values likeUNION SELECT,OR 1=1, or unusually long numeric fields. - Rollback guidance: if you cannot patch quickly, roll back to a version or deployment that does not expose this endpoint, or disable the bus lookup feature entirely.
- Watch for vendor updates and advisories: vendor advisory / project security notice.
Affected Versions
Nur-Alam39/bus-ticket@latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7badvulnerableNur-Alam39/bus-ticketwith no released fixed version currently known vulnerable- Safe versions:
TOD0_FIXED_VERSIONand later, or any release that replaces the raw SQL concatenation with prepared statements
Resolution Guide
1) Fix the code. Replace string concatenation with a prepared statement and validate the input as an integer.
<?php
$busid = filter_input(INPUT_POST, 'busid', FILTER_VALIDATE_INT);
if ($busid === false || $busid === null) {
http_response_code(400);
exit('Invalid busid');
}
$stmt = $conn->prepare('SELECT * FROM bus_info WHERE id = ?');
$stmt->bind_param('i', $busid);
$stmt->execute();
$result = $stmt->get_result();
?>
2) Harden the database account. Replace root access with a restricted user.
CREATE USER 'bus_app'@'localhost' IDENTIFIED BY 'CHANGE_ME_STRONG_PASSWORD';
GRANT SELECT ON bus_service.* TO 'bus_app'@'localhost';
FLUSH PRIVILEGES;
3) Common ecosystem commands. If this code is packaged in a project, update the application package or redeploy from a patched branch.
# npm / yarn / pnpm (if published as a package)
npm i bus-ticket@TODO_FIXED_VERSION
yarn add bus-ticket@TODO_FIXED_VERSION
pnpm add bus-ticket@TODO_FIXED_VERSION
# Python (if wrapped as a module)
pip install --upgrade bus-ticket==TODO_FIXED_VERSION
pipx upgrade bus-ticket
# Java (if distributed via Maven/Gradle coordinates)
mvn versions:use-latest-releases
./gradlew dependencies --refresh-dependencies
# Linux package managers (if your distro ships it)
sudo apt update && sudo apt install --only-upgrade bus-ticket
sudo yum update bus-ticket
# Docker
docker pull TODO_REGISTRY/bus-ticket:TODO_FIXED_TAG
docker run --rm TODO_REGISTRY/bus-ticket:TODO_FIXED_TAG
4) Config hardening. If you cannot patch immediately, disable the vulnerable feature or block the endpoint at the edge.
# Example reverse-proxy block
location = /bus_info.php {
return 403;
}
Detection & Verification
Check whether you are vulnerable:
# Search for the unsafe query pattern
grep -RIn "select \* from bus_info where id=\$busid" .
# Find direct mysqli_query usage around bus_info.php
grep -RIn "mysqli_query" bus_info.php .
# Look for root credentials in config files
grep -RIn "root" . | grep -E "password|passwd|db_user|db_pass"
Check logs for exploitation attempts:
grep -RInE "UNION SELECT|OR 1=1|--|%27|%3D" /var/log/nginx /var/log/apache2 /var/log/php*
Verify the fix: after patching, the following should fail or return no data as appropriate.
# Expected: rejected or harmless
curl -i -X POST https://YOUR_HOST/bus_info.php \
-d "busid=-1 UNION SELECT 1,2,3,4,5,6"
# Expected: valid integer works
curl -i -X POST https://YOUR_HOST/bus_info.php -d "busid=1"
Database-side verification: confirm the app no longer connects as root and only has the minimum permissions.
SELECT USER(), CURRENT_USER();
SHOW GRANTS FOR 'bus_app'@'localhost';
Risk and Impact
This flaw allows a remote, unauthenticated attacker to read arbitrary records from the database by injecting SQL through busid. Because the query runs in a numeric context and the app uses the MySQL root account, the blast radius can include passenger data, route data, credentials, and any other tables the database user can access.
Even though stacked queries are not allowed through mysqli_query(), UNION-based injection is enough to expose sensitive information and may enable further compromise if secrets or admin data are stored in the database.