PT-2026-92119 · Yonyou · Yonyou U8 Cloud

CVE-2023-54398

·

Published

2026-09-15

·

Updated

2026-09-16

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Yonyou U8 Cloud (affected versions not specified)
Description An unauthenticated Java deserialization issue exists in the nc.impl.pub.filesystem.FileManageServlet component. Remote attackers can execute arbitrary OS commands by sending a serialized payload via a POST request. The flaw occurs in the doAction() function, which passes raw HTTP request body data directly to ObjectInputStream.readObject() without filtering, leading to remote code execution. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-02-13.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-54398

Affected Products

Yonyou U8 Cloud