CVE-2026-40837 — An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getProjectScalings function due to improper neutralization of special elements in a SQL SELECT comma — CVE Database · The Intelligence Room