Junglewise Threat Intelligence

CVE-2026-94491: Yonyou KSOA SQL injection in search_list.jsp

CVE-2026-94491 · Severity: high · CVSS 7.3 · Published 2026-09-22

Vendors: Yonyou.

Executive brief

Yonyou KSOA is a business process management suite used by enterprises. A SQL injection vulnerability in the search_list.jsp component allows remote attackers to manipulate the address parameter and execute arbitrary SQL commands, potentially exposing or modifying sensitive business data. The vulnerability is publicly disclosed and exploit code is available.

Technical details

SQL injection vulnerability in /cardcase/search_list.jsp allows an unauthenticated remote attacker to execute arbitrary SQL queries by manipulating the address parameter. The vulnerability is network-accessible with no authentication required, enabling attackers to exfiltrate database contents or modify data. A fix status is unknown as the vendor did not respond to disclosure.

Affected products

  • Yonyou KSOA 9.0

Timeline

  • 2026-09-22: disclosed

References

Related threats