Junglewise Threat Intelligence

CVE-2026-94492: Yonyou U8cloud SQL injection in OpenAPI so.saleorder.sendaudit

CVE-2026-94492 · Severity: medium · CVSS 6.3 · Published 2026-09-22

Vendors: Yonyou.

Executive brief

Yonyou U8cloud is an enterprise cloud ERP platform used by mid-market and large organizations to manage finance, supply chain, sales, and collaboration. A SQL injection vulnerability in the /u8cloud/openapi/so.saleorder.sendaudit endpoint allows remote attackers to extract sensitive data from the database, potentially exposing customer, financial, and operational information without authentication.

Technical details

The OpenAPI endpoint /u8cloud/openapi/so.saleorder.sendaudit fails to properly sanitize the "operator" parameter, allowing SQL injection attacks via POST requests. An unauthenticated attacker can exploit this network-accessible endpoint to execute arbitrary SQL queries and retrieve sensitive database contents. The vulnerability has been publicly disclosed with functional exploit code available.

Affected products

  • Yonyou U8cloud 5.x

Timeline

  • 2026-07-14: disclosed: Exploit published publicly on GitHub
  • 2026-09-22: advisory: NVD entry published

References