High severity7.3NVD Advisory· Published Sep 29, 2026· Updated Sep 29, 2026
CVE-2026-102616
CVE-2026-102616
Description
A vulnerability was detected in risesoft-y9 WorkFlow-Engine up to 9.6.10. Impacted is the function getByIdAndYear of the file CustomHistoricProcessServiceImpl.java of the component OAuth2 Resource Filter. Performing a manipulation of the argument year/processInstanceId results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The sink is injectable on two independent positions, not just one. The vendor was contacted early about this disclosure but did not respond in any way.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=9.6.10
Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.