Sceawere

Vulnerability Detail

CVE-2026-94492UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Yonyou U8cloud SQL Injection Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
2h ago
Vendor
Yonyou
Product
U8cloud
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A security vulnerability has been detected in Yonyou U8cloud 5.x. This vulnerability affects unknown code of the file /u8cloud/openapi/so.saleorder.sendaudit of the component OpenAPI. The manipulation of the argument operator leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-09-22T01:16:56.253Z",
  "pubdate": "2026-09-22T01:16:56.253Z",
  "executiveSummary": "A critical SQL injection vulnerability has been identified within the Yonyou U8cloud 5.x platform, specifically impacting the OpenAPI component.\nThe vulnerability resides in the '/u8cloud/openapi/so.saleorder.sendaudit' endpoint, where the 'operator' parameter fails to implement adequate input validation or sanitization.\nThis flaw allows remote, unauthenticated attackers to inject arbitrary SQL commands into the backend database, potentially resulting in unauthorized data access, modification, or deletion.\nGiven the public disclosure of the exploit and the lack of a vendor response, the risk of exploitation by malicious actors is significant.\nThe vulnerability poses a severe threat to the confidentiality, integrity, and availability of the affected system, as successful exploitation could lead to full administrative compromise of the underlying database instance.\nOrganizations relying on U8cloud 5.x are at high risk, as the attack requires no specific user privileges and can be executed over the network.",
  "technicalDetails": "The vulnerability is rooted in an improper neutralization of special elements used in an SQL command within the 'operator' parameter of the '/u8cloud/openapi/so.saleorder.sendaudit' function. The OpenAPI component fails to employ parameterized queries or prepared statements when processing user-supplied input for database operations.\nWhen an attacker sends a crafted HTTP request to the vulnerable endpoint, the malicious payload contained within the 'operator' parameter is concatenated directly into the backend SQL statement. This allows the attacker to alter the query's logic, effectively bypassing existing authentication or input constraints.\nThe attack flow begins with the attacker identifying the target endpoint. By manipulating the 'operator' argument—for example, by appending SQL syntax such as 'UNION SELECT' or time-based blind injection payloads—the attacker forces the database to execute unintended commands.\nThis vulnerability is reachable remotely over standard network protocols, requiring no prior authentication. The execution context operates with the privileges of the database user configured for the U8cloud application, which often holds sufficient permissions to read, modify, or export sensitive business data residing in the U8cloud database.\nPost-exploitation, an attacker can extract full database schemas, sensitive customer records, or financial information stored within the U8cloud environment. In some scenarios, if database configurations permit, it may be possible to use the injection to interact with the underlying operating system, escalating the impact from a database-level breach to a full system compromise. The absence of vendor-supplied patches necessitates immediate manual intervention to mitigate the exposure of the exposed OpenAPI interface."
}
CVE-2026-94492: Yonyou U8cloud SQL Injection Vulnerability (MEDIUM Severity, CVSS: 6.3) | Sceawere