SQL Injection Vulnerability in Xinhu Rainrock RockOA Affected by Remote Exploits
CVE-2026-108571

6.9MEDIUM

Key Information:

Vendor

Xinhu

Vendor
CVE Published:
11 October 2026

What is CVE-2026-108571?

A vulnerability has been identified in the Xinhu Rainrock RockOA product up to version 2.7.6. The issue resides in the kqjcmdModel::returnchuli function located in the file webmain/task/openapi/openkqjAction.php. Through manipulation of the argument ID, an attacker can perform a SQL injection which allows unauthorized access and manipulation of the database. This security flaw can be exploited remotely, posing a significant risk to users. Publicly available exploit code increases the urgency for users to apply necessary mitigations. Despite the severity of the disclosure, the vendor has not responded to initial communications regarding this vulnerability.

Affected Version(s)

Rainrock RockOA 2.7.0

Rainrock RockOA 2.7.1

Rainrock RockOA 2.7.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

BlackSpdier (VulDB User)
VulDB CNA Team
.