CVE-2026-40834 — An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dash_layout.php files saveDashboardLayout function due to improper neutralization of special element — CVE Database · The Intelligence Room