CVE-2026-95829 | TDuckCloud tduck-platform up to 5.3 Pagination Inner Interceptor MybatisPlusConfig.java PaginationInnerInterceptor.concatOrderBy orders[0].column sql injection

SecurityVulns

A vulnerability, which was classified as critical, has been found in TDuckCloud tduck-platform up to 5.3. This vulnerability affects the function PaginationInnerInterceptor.concatOrderBy of the file tduck-api/src/main/java/com/tduck/cloud/api/config/MybatisPlusConfig.java of the component Pagination Inner Interceptor. The manipulation of the argument orders[0].column leads to sql injection.

This vulnerability is documented as CVE-2026-95829. The attack can be initiated remotely. Additionally, an exploit exists.

It is suggested to install a patch to address this issue.VulDB Recent EntriesRead More