Junglewise Threat Intelligence

CVE-2026-50782: Jinher OA C6 XXE injection in HrmAttendance module

CVE-2026-50782 · Severity: info · CVSS 7.5 · Published 2026-07-29

Executive brief

Jinher OA C6, an office automation platform, contains a security vulnerability in its attendance management module. An unauthorized attacker can exploit this flaw to remotely access and read sensitive files stored on the server. This could lead to the exposure of configuration data, system credentials, or other confidential business information.

Technical details

An XML External Entity (XXE) injection vulnerability exists within the Jinher OA C6 series. The flaw is located in the 'GetXmlHttp' endpoint of the 'sp_manager_getUserlist.aspx' page within the HrmAttendance module. The application fails to properly restrict or validate XML external entity references in incoming requests. An unauthenticated remote attacker can exploit this by sending a specially crafted XML payload, facilitating an out-of-band (OOB) attack to retrieve arbitrary files from the underlying server filesystem. No user interaction is required for exploitation.

Affected products

  • Jinher OA C6 C6 series

Timeline

  • 2026-03-26: disclosed: Initial disclosure via CNVD-2026-15669
  • 2026-07-29: advisory: CVE-2026-50782 published by NVD

References