---
id: CVE-2026-94491
title: A weakness has been identified in Yonyou KSOA 9.0
summary: >-
  A weakness has been identified in Yonyou KSOA 9.0. This affects an unknown
  part of the file /cardcase/search_list.jsp. Executing a manipulation of the
  argument address can lead to sql injection. It is possible to launch the
  attack remote…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
vendor: Yonyou
product: KSOA
affected:
  - KSOA 9.0
published: '2026-09-22'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T19:16:59.663'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94491'
references:
  - url: 'https://vuldb.com/cve/CVE-2026-94491'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/895364'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/408191'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/408191/cti'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/895364'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00254
epssPercentile: 0.17232
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-22T18:11:04.301674Z'
ingestedAt: '2026-09-22T00:55:54.016Z'
---

## Overview

A weakness has been identified in Yonyou KSOA 9.0. This affects an unknown part of the file /cardcase/search_list.jsp. Executing a manipulation of the argument address can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
