CVE-2026-7727Disclosure

LOWCVSS 6.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in Shandong Hoteam Software PDM Product Data Management System up to 8.3.9. This affects the function GetQueryMachineGridOnePageData of the file /Base/BaseService.asmx/DataService. This manipulation of the argument SortOrder causes sql injection. The attack can be initiated remotely. Upgrading to version 8.3.10 is able to mitigate this issue. You should upgrade the affected component.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-04); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-04: 2Mentions · 2026-05-24: 1Patch / Workaround · 2026-05-24: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-24: 105-0405-24
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-042
Disclosure2
2026-05-241
Patch1
Full discourse3 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH Severity: CVE-2026-7727 (CVSS 7.3) SQL injection flaw in Shandong Hoteam PDM ≤8.3.9 allows remote unauthenticated attacks via SortOrder parameter. ✅ Mitigation: Upgrade to v8.3.10 immediately #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/DGUEamZegc

    Post summary

    The tweet announces a high‑severity SQL injection (CVE‑2026‑7723) in Shandong Hoteam PDM 8.3.9 and below, with a CVSS score of 7.3, and urges users to immediately upgrade to version 8.3.10.

    0000056
    30 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7727 A vulnerability was determined in Shandong Hoteam Software PDM Product Data Management System up to 8.3.9. This affects the function GetQueryMachineGridOnePageData of t… https://www.cve.org/CVERecord?id=CVE-2026-7727 ----- Traducción: CVE-2026-7727 Se … http://infoflow.cloud`

    Post summary

    CVE-2026-7727 was disclosed as a vulnerability in Shandong Hoteam Software PDM Product Data Management System up to version 8.3.9, affecting the GetQueryMachineGridOnePageData function; no exploit or patch information was provided.

    0000033
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7727 A vulnerability was determined in Shandong Hoteam Software PDM Product Data Management System up to 8.3.9. This affects the function GetQueryMachineGridOnePageData of t… https://www.cve.org/CVERecord?id=CVE-2026-7727

    Post summary

    The post announces a vulnerability (CVE‑2026‑7727) affecting Shandong Hoteam Software PDM Product up to version 8.3.9, specifying the impacted function but providing no further technical or mitigation details.

    00000203
    57.4K followersView on X

Explore more