CVE-2026-44886: Pi.Alert: Web Interface Vulnerable to Unauthenticated Blind SQL Injection
Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. From 2024-06-29 to before 2026-05-07, the web application endpoint is vulnerable to SQL injection. The /pialert/php/server/devices.php route accepts requests from unauthenticated users when the action URL parameter is set to getDevicesTotals. The scansource URL parameter is then injected in a SQL query. This vulnerability is fixed in 2026-05-07.
Security readout for executives and security teams
Plain-English summary
Pi.Alert versions from 2024-06-29 before 2026-05-07 can expose device information through an unauthenticated SQL injection in the web interface. Attackers do not need login credentials or user interaction. The issue is serious because it can disclose database contents, but the provided sources do not show confirmed active exploitation.
Executive priority
Prioritize remediation for any internet-reachable or broadly reachable Pi.Alert instance. The business risk is unauthorized disclosure from a monitoring database, with no login required. Internal-only deployments still merit timely upgrade because public details are available.
Technical view
The /pialert/php/server/devices.php endpoint permits unauthenticated requests when action=getDevicesTotals. The scansource URL parameter is injected into a SQL query, creating blind SQL injection. The CVSS 4.0 score is 8.7 with network attack vector, low complexity, no privileges, and high confidentiality impact.
Likely exposure
Organizations running Pi.Alert builds dated from 2024-06-29 through before 2026-05-07 are potentially exposed, especially if the web interface is reachable from untrusted networks. Exposure is narrower if Pi.Alert is isolated to a trusted management LAN and access-controlled.
Exploitation context
The provided bundle identifies a public advisory and research write-up, but does not state in-the-wild exploitation. The CVE is not marked KEV in the supplied data. Treat public technical disclosure as increasing attacker awareness without assuming confirmed active campaigns.
Researcher notes
Evidence supports unauthenticated blind SQL injection in scansource for getDevicesTotals. The supplied CVSS emphasizes confidentiality impact, not integrity or availability. Do not infer broader Pi.Alert endpoints, exploit reliability, or compromise evidence beyond the provided CVE, advisory, and blog references.
Mitigation direction
Upgrade Pi.Alert to the 2026-05-07 fixed release or later.
Restrict Pi.Alert web access to trusted management networks only.
Block unauthenticated access to the Pi.Alert web interface where feasible.
Review the GitHub advisory for any updated vendor guidance.
Monitor for suspicious requests targeting devices.php with getDevicesTotals.
Validation and detection
Inventory Pi.Alert installations and record build dates.
Confirm no deployment runs versions from 2024-06-29 before 2026-05-07.
Check whether the web interface is reachable from untrusted networks.
Review web logs for unusual unauthenticated devices.php requests.
Use non-invasive version validation before considering production security testing.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-89: Database access and collection lookup
Injection into data stores can inform collection, data access, and exfiltration detection reviews. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-89 · source CWE mapping
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.