CVE-2026-1050Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in risesoft-y9 Digital-Infrastructure up to 9.6.7. This affects an unknown function of the file source-code/src/main/java/net/risesoft/util/Y9PlatformUtil.java of the component REST Authenticate Endpoint. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-04: 3Technical Details · 2026-02-04: 302-04
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Full discourse3 posts
  • Geng Yang@geng_zast
    General

    Authentication endpoints should never trust user input. We found one that did. This resulted in a SQL Injection. Here is the breakdown of CVE-2026-1050. https://t.co/rNPHEDLGQU

    Post summary

    A tweet points out a SQL injection flaw in an authentication endpoint (CVE‑2026‑1050) but provides no evidence of exploitation, PoC, or patch information.

    1000062
    45 followersView on X
  • Geng Yang@geng_zast
    Disclosure

    Target: Digital-Infrastructure (<= 9.6.7) Vuln: SQL Injection (CVE-2026-1050) Cause: Unsanitized String Concatenation. The vulnerability affects multiple auth endpoints, including /authenticate3 and /authenticate5.

    Post summary

    The post discloses a SQL Injection vulnerability (CVE‑2026‑1050) in Digital‑Infrastructure ≤9.6.7, affecting multiple authentication endpoints due to unsanitized string concatenation.

    1000030
    45 followersView on X
  • ZAST AI@zast_ai
    Disclosure

    The vulnerability (CVE-2026-1050) resides in Y9PlatformUtil. The application constructed SQL queries by concatenating strings ("..." + loginName + "...") rather than using bind variables.

    Post summary

    The text discloses that CVE-2026-1050 is a SQL injection vulnerability in Y9PlatformUtil caused by concatenating the loginName into SQL queries.

    1000033
    31 followersView on X

Explore more