CVE-2026-2682Disclosure(unigroup / electronic_archives_system)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). Impacted is an unknown function of the file /mine/PublicReport/prinReport.html?token=java. Such manipulation of the argument comid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • electronic_archives_system

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
electronic_archives_system

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-18: 2Technical Details · 2026-02-18: 102-18
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2682 SQL Injection in Tsinghua Unigroup Electronic Archives System via Token Parameter https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2682

    Post summary

    The post announces a newly disclosed SQL Injection vulnerability (CVE-2026-2682) affecting Tsinghua Unigroup's Electronic Archives System, with the flaw located in the token parameter. No exploitation details, patches, or PoC are provided.

    0001041
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2682 A vulnerability has been found in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). Impacted is an unknown function of the file /mine/PublicReport/p… https://www.cve.org/CVERecord?id=CVE-2026-2682

    Post summary

    A new vulnerability, CVE-2026-2682, has been reported in the Tsinghua Unigroup Electronic Archives System affecting an unknown function, with no further technical, exploitation, or mitigation details provided.

    00000107
    56.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appunigroupelectronic_archives_system---

Explore more