Unknown · Risesoft-Y9 Workflow-Engine · CVE-2026-102616
**Name of the Vulnerable Software and Affected Versions**
risesoft-y9 WorkFlow-Engine versions prior to 9.6.11
**Description**
An issue exists in the OAuth2 Resource Filter component within the `getByIdAndYear()` function of the `CustomHistoricProcessServiceImpl.java` file. Manipulation of the `year` and `processInstanceId` arguments allows for remote SQL injection, where an attacker can interfere with the queries that an application makes to its database. The injection point is available in two independent positions.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary mitigation, restrict access to the `getByIdAndYear()` function to minimize the risk of exploitation.