Junglewise Threat Intelligence

CVE-2026-75336: Funiture SQL injection in backend tool interfaces

CVE-2026-75336 · Severity: critical · CVSS 9.8 · Published 2026-08-26

Executive brief

Funiture is an open-source Java e-commerce system used to build online retail platforms. The backend tool interfaces contain SQL injection vulnerabilities that allow authenticated administrators to execute arbitrary SQL commands, resulting in complete database compromise, including theft of password hashes and persistent backdoor installation.

Technical details

The vulnerability is a SQL injection flaw in the backend tool interfaces /sys/tool/select.json and /sys/tool/update.json within the SysToolController class. User-supplied SQL parameters are directly concatenated into MyBatis queries using the ${sql} dynamic string substitution with no parameterization or input validation. The attack requires an authenticated admin session (e.g., default credentials admin/123456). An authenticated attacker can execute arbitrary SQL statements to read/write the entire database, extract password hashes, or establish persistent backdoors. The vulnerable component is part of the Spring MVC + MyBatis framework in version 1.0.0.

Affected products

  • Funiture Funiture 1.0.0

Timeline

  • 2026-08-26: disclosed

References