CVE-2026-94492: Yonyou U8cloud OpenAPI so.saleorder.sendaudit sql injection
A security vulnerability has been detected in Yonyou U8cloud 5.x. This vulnerability affects unknown code of the file /u8cloud/openapi/so.saleorder.sendaudit of the component OpenAPI. The manipulation of the argument operator leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need?
The CVSS vector indicates low privileges are required (PR:L). The attack can be initiated remotely and does not require user interaction.
Which deployments should be considered exposed?
The affected product is Yonyou U8cloud 5.x, specifically the OpenAPI endpoint at /u8cloud/openapi/so.saleorder.sendaudit. The provided data does not establish whether this endpoint is enabled or reachable in a default configuration.
Is public exploitation a concern?
Yes. Public exploit disclosure has been reported, and the available information says the exploit may be used.
How can defenders identify potential exploitation?
Review requests to /u8cloud/openapi/so.saleorder.sendaudit, particularly authenticated requests containing the operator argument. The provided data does not include specific payloads, indicators of compromise, or logging signatures.