SECURITYCRITICALCVE-2026-63713

CVE-2026-63713: Time-Based Blind SQL Injection in Toptech TMS7 and TopHAT Audit Logs

Critical CVSS 9.0 time-based blind SQL injection in Toptech TMS7/TopHAT audit log search hits fuel terminal ICS/OT systems worldwide; patched in 7.8.

Dylan H.

Security Team

September 30, 2026
9 min read
CVE-2026-63713: Time-Based Blind SQL Injection in Toptech TMS7 and TopHAT Audit Logs

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • Toptech Systems TMS7, version 7.6.3 (and earlier deployments not yet upgraded to 7.8)
  • Toptech Systems TopHAT, version 7.6.3 (and earlier deployments not yet upgraded to 7.8)

Overview

The Cybersecurity and Infrastructure Security Agency (CISA) has published ICS advisory ICSA-26-272-02, disclosing CVE-2026-63713, a critical-severity time-based blind SQL injection vulnerability in Toptech Systems' TMS7 and TopHAT terminal management software. Per the official description, "the search parameter in the view audit logs feature within the utilities section is susceptible to a time-based blind SQL injection vulnerability." The flaw was published September 29, 2026 (reserved August 10, 2026) and carries a CVSS 3.1 score of 9.0 (Critical), vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H; CISA also lists a CVSS 4.0 score of 8.5, vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H.

TMS7 is not a consumer-facing product — it is a terminal management hub used by fuel and bulk-liquid terminal operators to run stock accounting, allocations, and remote access/control over entry gates, load racks, and bill-of-lading (BOL) printers. TopHAT is the companion multi-site console that lets operators managing multiple terminals administer them from a single pane. According to Toptech, the platform is deployed at over 1,200 terminals worldwide, and CISA's advisory lists the affected sectors as Energy, Chemical, and Transportation Systems — squarely inside critical infrastructure and operational technology (OT) territory rather than a typical web application.

CVE-2026-63713 is not an isolated finding. It is one of ten vulnerabilities disclosed together in ICSA-26-272-02 — seven rated Critical, one High, and two Low — discovered and reported by Sachin Shetty and Roy Duisters of Shell CyberDefence. The most severe of the batch, CVE-2026-71379, scores a full CVSS 10.0 and reportedly requires no credentials at all. CVE-2026-63713 sits among five separate injection points (spanning search, audit log, transaction, and report functionality) that CISA says are all exploitable via time-based blind SQL injection — a pattern consistent with a single, systemic input-handling gap across TMS7's web interface rather than one isolated bug.

Notably, Toptech had already shipped a fix before the public CVE record went live: the vendor's security advisory and blog post announcing TMS7 / TopHAT 7.8 — described as having "strengthened security" — is dated July 20, 2026, roughly two months ahead of the September 29 CISA/NVD publication. Organizations that have not tracked Toptech's own release notes independently of CVE feeds may still be running the vulnerable 7.6.3 line today.


Technical Details

AttributeValue
CVE IDCVE-2026-63713
SeverityCritical
CVSS 3.1 Score9.0 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H)
CVSS 4.0 Score8.5 (CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H)
Attack VectorNetwork
Authentication / PrivilegesHigh (PR:H) — requires an authenticated account with elevated access to the Utilities section; no victim interaction needed (UI:N)
CWECWE-89 — Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)
Component/Function"View Audit Logs" feature, Utilities section — the search parameter
Injection TechniqueTime-based blind (response-timing side channel; no direct error output or data reflected to the attacker)
Affected VersionsTMS7 and TopHAT 7.6.3
Fixed VersionTMS7 and TopHAT 7.8 (vendor advisory dated 2026-07-20)
Exploit StatusNo public proof-of-concept and not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog as of September 30, 2026
Reported BySachin Shetty and Roy Duisters, Shell CyberDefence
AssignerICS-CERT

How It Works

Time-based blind SQL injection, explained

Unlike classic SQL injection, where an attacker sees database errors or reflected query output directly in the response, blind SQL injection gives the attacker no such feedback. In the time-based variant, the attacker instead injects conditional logic that forces the database to pause — for example, a SLEEP() or WAITFOR DELAY call — only when a guessed condition is true. By measuring how long the server takes to respond, the attacker can infer the value of a single character, then repeat the process thousands of times to reconstruct entire rows of data. It is slow and noisy, but it works against applications that suppress error messages, and it requires nothing more than a stopwatch and patience once the injection point is confirmed.

The vulnerable path

  1. TMS7's Utilities section exposes a "View Audit Logs" screen intended to let terminal administrators search historical activity records.
  2. The screen's search parameter is passed into a backend SQL query without adequate sanitization or parameterization.
  3. An attacker who already holds an account with elevated privileges (PR:H in the CVSS vector — this is not an unauthenticated flaw) submits a crafted search value containing a time-delay SQL payload, such as a string ending in a conditional SLEEP(10) clause.
  4. By observing whether the response is delayed, the attacker confirms the injection works, then iterates character-by-character to extract data from the audit log tables — and potentially, depending on database permissions, from other tables reachable via the same connection.
  5. Because the CVSS vector marks Scope Changed (S:C) and Availability: High (A:H), a successful exploit chain can reach beyond the audit log data itself — consistent with either lateral movement within the database or an attacker driving the database into resource exhaustion through repeated heavy queries.

Why this matters more than a typical admin-panel SQLi

TMS7 and TopHAT are operational technology for fuel and bulk-liquid terminals — the audit log database sits alongside systems that track stock accounting, gate access, load-rack control, and BOL printing. A database compromise at a fuel terminal is not just a data-privacy incident; depending on what else shares that database tier, it can expose operational records relevant to physical product movement and access control at critical-infrastructure sites. That context is also why CISA classifies this under the Energy, Chemical, and Transportation Systems sectors rather than as a generic enterprise-IT bug, and why it was disclosed as part of a coordinated ten-vulnerability advisory rather than a single CVE.


Impact Assessment

Impact AreaDescription
ConfidentialityRated High — time-based blind SQLi can be used to systematically extract audit log contents and potentially other data reachable from the same database connection
IntegrityRated Low per the CVSS vector, but the underlying access could still be abused for limited data manipulation depending on database permissions
AvailabilityRated High — repeated time-delay queries or a pivot to more damaging statements can degrade or disrupt the application/database for legitimate terminal operators
Privilege RequirementRequires an already-authenticated account with elevated (Utilities-section) access — this limits exposure to insiders, compromised operator credentials, or attackers who have already gained a foothold
Critical Infrastructure ExposureTMS7/TopHAT manage fuel and bulk-liquid terminal operations across the Energy, Chemical, and Transportation Systems sectors, per CISA — a data or availability impact here carries OT-adjacent risk, not just IT risk
Batch Severity ContextOne of ten vulnerabilities in the same advisory; the companion CVE-2026-71379 scores a maximum CVSS 10.0 and is reported to require no credentials, meaning environments vulnerable to CVE-2026-63713 should assume they are also exposed to more severe, lower-barrier flaws in the same release line

Recommendations

For Toptech TMS7 / TopHAT operators

  1. Identify every TMS7 and TopHAT instance in your environment and confirm the running version. Any deployment still on 7.6.3 or earlier should be treated as vulnerable.
  2. Upgrade to version 7.8 immediately. Toptech's fix has been publicly available since July 20, 2026 — well before the CVE and CISA advisory were published — so there is no reason to delay patching pending further vendor guidance.
  3. Take TMS7/TopHAT off the public internet until patched. CISA's general guidance for this advisory is to ensure control-system devices are not directly internet-accessible; place them behind a firewall, isolated from business networks, and reachable only via VPN when remote access is required.
  4. Review accounts with Utilities-section access. Because exploitation requires elevated privileges, auditing who holds that access — and tightening it to least-privilege — meaningfully reduces the attack surface even before patching completes.

For security teams at terminal operators

  1. Treat this as one of ten related findings. Patching to 7.8 should be validated against the full ICSA-26-272-02 advisory, not just this single CVE, since the same release addresses multiple injection points (search, audit log, transaction, and report parameters) and the maximum-severity companion flaw.
  2. Monitor for anomalous response-timing patterns or unusual audit-log search activity from authenticated accounts — the classic signature of time-based blind SQLi probing.
  3. Log and alert on database performance anomalies coinciding with Utilities-section usage, since a time-based injection campaign generates a distinctive pattern of slow, repeated queries.
  4. Coordinate with OT/ICS security processes, not just IT vulnerability management — this advisory falls under CISA's ICS program and affects sectors with regulatory and safety considerations beyond typical enterprise patching cadences.

Key Takeaways

  1. CVE-2026-63713 is a CVSS 9.0 Critical time-based blind SQL injection (CWE-89) in the search parameter of the View Audit Logs feature in Toptech Systems' TMS7 and TopHAT, terminal management software used at fuel and bulk-liquid terminals.
  2. Exploitation requires an authenticated account with elevated privileges (PR:H) but no user interaction, and can be performed remotely over the network.
  3. Version 7.6.3 is affected; Toptech fixed the issue in version 7.8, released via vendor advisory on July 20, 2026 — ahead of the CVE's September 29, 2026 public disclosure.
  4. This CVE is one of ten vulnerabilities disclosed together in CISA ICS advisory ICSA-26-272-02 (seven Critical, one High, two Low), reported by Shell CyberDefence; the worst in the set, CVE-2026-71379, scores a maximum CVSS 10.0.
  5. CISA lists the affected sectors as Energy, Chemical, and Transportation Systems, with TMS7 deployed at over 1,200 terminals worldwide — this is an OT-adjacent, critical-infrastructure advisory, not a generic web-app bug.
  6. No public exploit code or confirmed in-the-wild exploitation has been reported as of September 30, 2026, and the CVE is not on CISA's KEV catalog — but given the coordinated multi-CVE disclosure and the availability of a patch since July, organizations should upgrade to 7.8 without waiting for signs of active exploitation.

Sources

CosmicBytez Labs will update this advisory if Toptech publishes additional technical detail or if active exploitation of CVE-2026-63713 is confirmed.