CVE-2026-7672Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security vulnerability has been detected in youlaitech youlai-boot up to 2.21.1. This affects the function getUserList of the file src/main/java/com/youlai/boot/system/controller/UserController.java of the component Users Endpoint. Such manipulation of the argument order leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-05-03: 4Technical Details · 2026-05-03: 205-03
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets4 URLs
Full discourse4 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-7672 📊 Severity: 6.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7672 #CVE-2026-7672 #CVE #Medium #CyberSecurity #InfoSec https://t.co/ZYQ29USPV4

    Post summary

    The tweet is a brief CVE alert for CVE-2026-7672, noting its severity (6.3) and medium risk level, with no additional technical or exploit information.

    0000038
    151 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7672 A security vulnerability has been detected in youlaitech youlai-boot up to 2.21.1. This affects the function getUserList of the file src/main/java/com/youlai/boot/syste… https://www.cve.org/CVERecord?id=CVE-2026-7672 ----- Traducción: CVE-2026-7672 Se … http://infoflow.cloud`

    Post summary

    CVE-2026-7672 has been identified for youlaitech youlai‑boot up to version 2.21.1, affecting the getUserList function in the application.

    0000028
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7672 A security vulnerability has been detected in youlaitech youlai-boot up to 2.21.1. This affects the function getUserList of the file src/main/java/com/youlai/boot/syste… https://www.cve.org/CVERecord?id=CVE-2026-7672

    Post summary

    A new vulnerability (CVE-2026-7672) was identified in Youlaitech Youlai‑boot up to version 2.21.1, impacting the getUserList function in the project's source code.

    00000277
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-7672 SQL Injection in Youlaitech Youlai-Boot Up To 2.21.1 Users Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7672

    Post summary

    The text lists CVE‑2026‑7672 as an SQL injection in Youlaitech Youlai‑Boot up to version 2.21.1, but provides no PoC, exploit, patch, or active exploitation details.

    0000050
    4.0K followersView on X

Explore more