Ghostwire

CVE-2026-94491: A weakness has been identified in Yonyou KSOA 9.0. This affects an unknown part of the file /cardcase/search_list.jsp....

HIGH CVSS 7.3 EPSS 0.25% Exploit Available

Published: September 22, 2026 | Last Modified: September 22, 2026

Description

A weakness has been identified in Yonyou KSOA 9.0. This affects an unknown part of the file /cardcase/search_list.jsp. Executing a manipulation of the argument address can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Ghostwire Analysis — What This Means Practically

Exploitation Probability (EPSS): Low — 0.25% (17th percentile)

Low exploitation probability based on current threat landscape data. Standard patching timeline is appropriate.

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

References