CVE-2026-40835 — An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the saveObjectFromData function due to improper neutralization of special elements in a SQL SELECT comma — CVE Database · The Intelligence Room