CVE-2026-4289Disclosure

LOWCVSS 5.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (6 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A security vulnerability has been detected in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This affects an unknown function of the file /rest/preSetTemplate/getRecByTemplateId. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 6 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • 6 total mentions across 1 day

Deep dive

Activity timeline6 mentions / 1d
02356Mentions · 2026-03-17: 6Active Exploitation · 2026-03-17: 1Technical Details · 2026-03-17: 303-17
Signal classification3 categories
Disclosure
350.0%
General
233.3%
Active Exploitation
116.7%
Referenced assets6 URLs
Full discourse6 posts
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4289 - Tiandy Easy7 Integrated Management Platform getRecByTemplateId sql injection Intel Report: https://ift.tt/2zPra09

    Post summary

    A threat alert for CVE-2026-4289 highlights a SQL injection flaw in Tiandi Easy7's getRecByTemplateId endpoint, with an intel report link for further details.

    0001048
    336 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4289 A security vulnerability has been detected in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This affects an unknown function of the file /rest/preSetTemplat… https://www.cve.org/CVERecord?id=CVE-2026-4289

    Post summary

    The text announces that CVE-2026-4289 has been detected in Tiandy Easy7 Integrated Management Platform up to version 7.17.0, but offers no further technical or remedial details.

    0001073
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4289 SQL Injection Vulnerability in Tiandy Easy7 Integrated Management Platform Up to 7.17.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4289

    Post summary

    A new SQL injection vulnerability, CVE-2026-4289, affecting Tiandy Easy7 Integrated Management Platform versions up to 7.17.0 has been disclosed via a reference link.

    0001043
    4.0K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Some increased actor activities are shown targeting Tiandy Easy7 Integrated Management Platform (CVE-2026-4289) https://vuldb.com/?ctiid.351294

    Post summary

    Actor activity appears to have increased against the Tiandy Easy7 platform, indicating potential active exploitation of CVE‑2026‑4289.

    0000070
    2.1K followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-4289 - Tiandy - Easy7 Integrated Management Platform - https://www.redpacketsecurity.com/cve-alert-cve-2026-4289-tiandy-easy7-integrated-management-platform/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-4289 #tiandy #easy7-integrated-management-platform

    Post summary

    The post announces a CVE headline and links to an external page; it lacks any specific technical details, exploit code, or mitigation information.

    0000076
    3.6K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-4289 📊 Severity: 7.3 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4289 #CVE-2026-4289 #CVE #High  #CyberSecurity #InfoSec https://t.co/j9kOZMDQTR

    Post summary

    The tweet alerts about CVE-2026-4289 with a 7.3 CVSS score and high risk level, but offers no exploitation details, PoC, or mitigation guidance.

    0000054
    101 followersView on X

Explore more