Overview
Toptech Systems, a US-based vendor whose TMS7 and TopHAT platforms provide terminal management and automation software for fuel and bulk-liquid terminal operations — truck-rack loading authorizations, product inventory, and custody-transfer transaction handling — has disclosed CVE-2026-68068, a critical-severity SQL injection vulnerability. The flaw was published as part of CISA ICS Advisory ICSA-26-272-02 on September 29, 2026, alongside nine sibling CVEs affecting the same product line, all reported against TMS7/TopHAT version 7.6.3 and fixed together in the vendor's version 7.8 release.
Per the advisory, the screenID parameter in the electronic transaction queue viewer — part of the application's manual transactions section, where terminal operators review and manually intervene in loading transactions — is vulnerable to a time-based blind SQL injection. Because TMS7/TopHAT is deployed across the energy, chemical, and transportation systems sectors worldwide to run physical terminal operations, a successful attack against this class of software carries operational-technology risk well beyond a typical web-application data breach.
The vulnerability carries a CVSS 3.1 score of 9.0 (Critical), vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H, and a CVSS 4.0 score of 8.5 (High), vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H. Both scoring systems describe the same shape of risk: a network-reachable, low-complexity attack that needs no victim interaction, but does require the attacker to already hold high privileges (PR:H) within the application — this is a post-authentication flaw, not an open, unauthenticated hole. CISA assigned the CVE (assigner icscert) after the issue was reserved on August 10, 2026.
CVE-2026-68068 was reported to Toptech and CISA by Sachin Shetty and Roy Duisters of Shell CyberDefence — a researcher affiliation that tracks closely with TMS7/TopHAT's real-world use at fuel-terminal operators. Toptech notified customers of the issue batch on July 20, 2026, and shipped the consolidated fix in version 7.8, with a vendor blog post published the following month detailing the security-hardening work behind the release. No public proof-of-concept exploit and no confirmed in-the-wild exploitation have been reported as of this writing, and the CVE does not currently appear in CISA's Known Exploited Vulnerabilities (KEV) catalog.
Technical Details
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-68068 |
| Severity | Critical |
| CVSS v3.1 Score | 9.0 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H) |
| CVSS v4.0 Score | 8.5 High (CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H) |
| Attack Vector | Network |
| Privileges Required | High (PR:H) — valid, authenticated application access needed |
| User Interaction | None (UI:N) |
| CWE | CWE-89 — Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) |
| Vulnerable Parameter | screenID — electronic transaction queue viewer, manual transactions section |
| Vulnerability Class | Time-based blind SQL injection |
| Assigner | icscert (CISA) |
| Advisory | CISA ICSA-26-272-02, "Toptech TMS7 and TopHAT" |
| Reported By | Sachin Shetty and Roy Duisters, Shell CyberDefence |
| Exploit Status | No public PoC detected; not listed in CISA's KEV catalog as of September 30, 2026 |
How It Works
Time-based blind SQL injection, explained
Unlike a classic SQL injection where an application echoes database query results or verbose error messages back to the attacker, a blind SQL injection gives the attacker no direct output to read. A time-based blind variant works around that by injecting conditional logic into the query that forces the database to pause — for example, via a SLEEP() or WAITFOR DELAY-style construct — only when a guessed condition evaluates true. The attacker then infers the answer purely from how long the response takes, repeating the process character by character to reconstruct data such as table names, column contents, or credential hashes, entirely through a timing side channel.
Why the queue viewer and screenID matter
The electronic transaction queue viewer is a routine, actively used operator screen inside TMS7/TopHAT's manual transactions module — where terminal staff review, re-queue, or manually intervene in fuel and bulk-liquid loading transactions such as truck-rack authorizations and product releases. Because this is a standard part of day-to-day terminal operations rather than a locked-down administrative panel, screenID is reachable by any account with the access level ordinarily granted for transaction review, which lines up with the PR:H (high, but not necessarily administrator-tier) privilege requirement in the CVSS vector.
The attack chain
- An attacker obtains valid TMS7/TopHAT credentials — through phishing, credential stuffing, reused passwords, or lateral movement from another compromised system on the terminal's network — sufficient to reach the manual transactions section.
- The attacker supplies a crafted value in the
screenIDparameter designed to alter the structure of the backend SQL query, for example appending conditional logic and a delay function. - Because the application does not reflect query results or database errors back to the attacker, the attacker instead measures response-time differences: a delayed response confirms a guessed condition was true, while a fast response confirms it was false.
- By repeating this technique across many requests, the attacker can enumerate database contents — user accounts, password hashes, transaction records, terminal configuration data — one bit or character at a time, without ever seeing a query result or error message directly.
- With Scope Changed (
S:C) and High confidentiality plus High availability impact under CVSS 3.1, a sustained attack could extend beyond simple data theft into denial-of-service against the database backing multiple TMS7/TopHAT modules, given the volume of timing-based requests such an extraction typically requires.
Part of a larger disclosure batch
CVE-2026-68068 is one of ten vulnerabilities (seven critical, one high, two low) disclosed together in ICSA-26-272-02, and it is not an isolated finding. Two sibling issues are close structural twins: CVE-2026-63713 (time-based blind SQL injection via the search parameter in the utilities section's audit-log viewer) and CVE-2026-68954 (time-based blind SQL injection via the pattern parameter on the TMS application's home page search). CVE-2026-72510 (supplier_no parameter) and CVE-2026-72507 (reportType parameter) round out a cluster of five SQL injection CVEs in the same batch — a pattern that points to a systemic lack of parameterized queries across multiple TMS7/TopHAT modules rather than a single isolated coding mistake. It's also worth noting the advisory's most severe finding, CVE-2026-71379 (CVSS 10.0), allows unauthenticated database export in the same release — which matters for risk triage, since an attacker targeting an unpatched terminal may not need to phish credentials first if a pre-authentication path to the same underlying database already exists.
Impact Assessment
| Impact Area | Description |
|---|---|
| Data Confidentiality | Rated High — an attacker can enumerate the full backend database, including credentials, transaction history, and terminal configuration, via the timing side channel |
| Data Integrity | Rated Low under CVSS 3.1, but successful enumeration of credentials or session data could enable follow-on write access through other application functions |
| Availability | Rated High — the volume of requests required for timing-based extraction, or deliberate abuse of injected delay functions, can degrade or exhaust database performance |
| Operational Technology Exposure | TMS7/TopHAT drives real fuel and bulk-liquid terminal transactions; corrupted or stale transaction-queue data has downstream effects on truck-rack loading and custody-transfer accuracy, not just IT data |
| Sector Risk | CISA lists deployments across energy, chemical, and transportation systems sectors worldwide — a compromised terminal management system is a supply-chain concern, not just a single-site issue |
| Batch Risk | Disclosed alongside four other SQL injection CVEs and a CVSS 10.0 unauthenticated database-export flaw (CVE-2026-71379) in the same release, meaning unpatched instances face multiple independent paths to the same underlying data |
Recommendations
For Toptech TMS7/TopHAT operators
- Inventory every TMS7 and TopHAT instance in your environment and confirm the running version against CISA advisory ICSA-26-272-02.
- Upgrade to version 7.8 or later, the release Toptech confirmed addresses this vulnerability and its nine siblings, following your standard change-management process for terminal-automation systems.
- Review accounts with access to the manual transactions and utilities sections — since exploitation requires
PR:H-level authenticated access, auditing who holds transaction-review privileges materially reduces the attack surface until patched. - Segment terminal-automation networks from general business IT networks and the internet, consistent with CISA's standing ICS guidance; require VPN access for any remote administration.
- Treat database query logs as a detection source — unusual, high-volume, or slow-responding queries against
screenID-style parameters can indicate time-based blind SQL injection attempts in progress.
For security teams
- Prioritize this alongside the other four SQL injection CVEs in ICSA-26-272-02 (CVE-2026-63713, CVE-2026-68954, CVE-2026-72510, CVE-2026-72507) — patch as a single batch rather than triaging each CVE individually, since they share the same root cause and fix.
- Cross-reference with CVE-2026-71379 (CVSS 10.0, unauthenticated database export) when scoping risk — an unpatched environment may be exposed through a pre-authentication path regardless of credential hygiene.
- Monitor for anomalous authentication activity against TMS7/TopHAT accounts, particularly credential stuffing or reuse patterns, given the
PR:Hrequirement makes account compromise the most likely path to exploitation. - Subscribe to CISA ICS advisories for Toptech Systems and related terminal-automation vendors to catch follow-on disclosures.
For terminal operations staff
- Use unique, non-reused credentials for TMS7/TopHAT accounts, and enable multi-factor authentication where the platform supports it.
- Report unexpected slowness or unusual behavior in the transaction queue viewer or other manual-transactions screens — it may be the only visible symptom of a timing-based attack in progress.
- Coordinate the version 7.8 upgrade with IT/OT security teams rather than deferring it as a routine software update, given the sensitivity of the systems involved.
Key Takeaways
- CVE-2026-68068 is a CVSS 9.0 Critical time-based blind SQL injection (CWE-89) in the
screenIDparameter of Toptech TMS7 and TopHAT's electronic transaction queue viewer, disclosed September 29, 2026. - TMS7/TopHAT are terminal management and automation platforms used to run fuel and bulk-liquid terminal transactions across the energy, chemical, and transportation systems sectors — a vendor/product identity not stated in the raw NVD description but confirmed via CISA ICS Advisory ICSA-26-272-02.
- Exploitation requires authenticated access with high privileges (
PR:H) but no victim interaction — this is a post-auth flaw, making credential hygiene and access review the most direct mitigations short of patching. - It was disclosed as part of a ten-CVE batch against the same TMS7/TopHAT release, including four other SQL injection issues and a CVSS 10.0 unauthenticated database-export flaw (CVE-2026-71379) — treat the batch as a single remediation effort.
- Version 7.8, released by Toptech in mid-2026, fixes all ten vulnerabilities in the advisory; affected organizations should prioritize upgrading from version 7.6.3.
- No confirmed in-the-wild exploitation or public proof-of-concept has been reported as of September 30, 2026, and the CVE is not currently on CISA's KEV catalog — but the researcher affiliation (Shell CyberDefence) and the software's real-world deployment at fuel terminals underscore that this is squarely a critical-infrastructure risk, not a theoretical one.
Sources
- NVD — CVE-2026-68068
- CISA ICS Advisory ICSA-26-272-02 — Toptech TMS7 and TopHAT
- Toptech Systems — TMS7 Version 7.8 Strengthens Security
- NVD — CVE-2026-63713 (sibling SQL injection finding)
CosmicBytez Labs will update this advisory if Toptech Systems or CISA publish additional technical detail, or if active exploitation of CVE-2026-68068 is confirmed.