fx4tqqfvdw4.feishu.cnexploit
https://fx4tqqfvdw4.feishu.cn/docx/ETWUdbPk1oCC56xoEWHc3Q28nEc?from=from_copylink CVE-2026-4594
MEDIUM
erupts erupt EruptJpaUtils.java geneEruptHqlOrderBy sql injection
Record summary
CVE-2026-4594 has a selected CVSS score of 6.9 (medium).
Description
A vulnerability has been found in erupts erupt up to 1.13.3. Affected by this issue is the function geneEruptHqlOrderBy of the file erupt-data/erupt-jpa/src/main/java/xyz/erupt/jpa/dao/EruptJpaUtils.java. Such manipulation of the argument sort.field leads to sql injection hibernate. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 24, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | 1.13.0 | affected | |
| 1.13.1 | affected | ||
| 1.13.2 | affected | ||
| 1.13.3 | affected |
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-4594 VDB-352431 | CTI Indicators (IOB, IOC, IOA)signaturepermissions required
https://vuldb.com/?ctiid.352431 VDB-352431 | erupts erupt EruptJpaUtils.java geneEruptHqlOrderBy sql injectionvdb entryTechnical description
https://vuldb.com/?id.352431 Submit #775594 | erupts erupt erupt <= 1.13.3 Improper Input ValidationThird-party advisory
https://vuldb.com/?submit.775594