CVE-2026-95829 Details
Description
A vulnerability was identified in TDuckCloud tduck-platform up to 5.3. This vulnerability affects the function PaginationInnerInterceptor.concatOrderBy of the file tduck-api/src/main/java/com/tduck/cloud/api/config/MybatisPlusConfig.java of the component Pagination Inner Interceptor. The manipulation of the argument orders[0].column leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used. The identifier of the patch is ea7f0fae7cb0fd998a3284c11addce689350cd69. It is suggested to install a patch to address this issue.
A SQL injection vulnerability has been identified in TDuckCloud tduck-platform versions through 5.3. The issue arises in the Pagination Inner Interceptor component, specifically within the PaginationInnerInterceptor.concatOrderBy function. The vulnerability allows for remote exploitation by manipulating the orders[0].column argument, leading to SQL injection.
Users are advised to update to TDuckCloud tduck-platform version 5.4 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 23, 2026CISA-ADP
Assessed Sep 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/TDuckCloud/tduck-survey-form/commit/ea7f0fae7cb0fd998a3284c11addce689350cd69 | [email protected] | Source CodeVendor |
| https://vuldb.com/cve/CVE-2026-95829 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/897248 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/408522 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/408522/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-74 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | [email protected] |
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| TDuckCloud tduck-platform | <= 5.3 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 26, 2026 | CVE Modified | CISA-ADP |
| Sep 23, 2026 | New CVE Received | [email protected] |
Volerion