CVE-2026-9524: xianrendzw EasyReport REST Endpoint execute sql injection

Published May 26, 2026
·
Updated

A flaw has been found in xianrendzw EasyReport up to 2.0.17.0522Beta. Affected by this issue is the function execute of the component REST Endpoint. Executing a manipulation of the argument reportParams can lead to sql injection. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Software

1 affected component
xianrendzw EasyReport<=2.0.17.0522_Beta

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove xianrendzw EasyReport from your environment.

    Uninstall or take the EasyReport installation offline if the application is not required or cannot be securely operated.

  2. Configuration

    Disable the REST 'execute' endpoint (or otherwise disable processing of reportParams) until a vendor patch or code fix is available.

    xianrendzw EasyReport REST Endpoint execute endpoint = disabled
  3. Compensating control

    Restrict access to the application REST interface to trusted IPs via firewall/ACLs and place the service behind a WAF or similar detection/prevention layer configured to block SQL injection payloads.

  4. Compensating control

    If you maintain the code, implement input validation and use parameterized queries/prepared statements for handling reportParams to eliminate SQL injection vectors; deploy these code changes as soon as possible.

  5. Operational

    Monitor application and database logs for signs of exploitation, perform incident response if suspicious activity is found, and rotate any credentials or secrets that may have been exposed.

Event History

May 26, 2026
CVE Published
via MITRE·02:45 AM
Data Sourced
via MITRE·02:45 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 AM
DescriptionSeverityWeakness
Mar 25, 58386
Event
via FIRST·04:30 PM

Frequently Asked Questions

1

What is the severity of CVE-2026-9524?

The severity of CVE-2026-9524 is rated medium with a score of 6.3.

2

What is the impact of CVE-2026-9524?

CVE-2026-9524 allows for remote SQL injection through manipulation of the reportParams argument.

3

How do I fix CVE-2026-9524?

To fix CVE-2026-9524, update xianrendzw EasyReport to the latest version that addresses the SQL injection vulnerability.

4

What type of vulnerability is CVE-2026-9524?

CVE-2026-9524 is classified as a SQL Injection vulnerability.

5

Who is affected by CVE-2026-9524?

Users of xianrendzw EasyReport versions up to 2.0.17.0522_Beta are affected by CVE-2026-9524.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203