PT-2026-97115 · Tduckcloud · Tduck-Platform

·

CVE-2026-95829

·

Published

2026-09-22

·

Updated

2026-09-23

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TDuckCloud tduck-platform versions prior to 5.4
Description Remote SQL injection is possible through the manipulation of the orders[0].column argument within the PaginationInnerInterceptor.concatOrderBy() function, located in the tduck-api/src/main/java/com/tduck/cloud/api/config/MybatisPlusConfig.java file of the Pagination Inner Interceptor component.
Recommendations Install the patch with identifier ea7f0fae7cb0fd998a3284c11addce689350cd69 for versions prior to 5.4.

Fix

SQL injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-95829

Affected Products

Tduck-Platform