CVE-2026-79573
Deferred Deferred - Pending Action

SQL Injection in L-ONE Application

Vulnerability report for CVE-2026-79573, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-14

Assigner: MITRE

Description

L-ONE v1.0.0 was discovered to contain multiple SQL injection vulnerabilities in the /attachment/getBusinessUploadList component via the busid, id, and taskid parameters. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jfinaloa jfinal 4.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-79573 is a SQL injection vulnerability in L-ONE v1.0.0, an open-source Java-based office automation system. The flaw exists in the /attachment/getBusinessUploadList component where user inputs like busid, id, and taskid are directly used in SQL queries without proper sanitization. Attackers can inject malicious SQL statements to access sensitive database information.

Impact Analysis

This vulnerability allows attackers with basic user permissions to exploit SQL injection after login. They can extract sensitive database data, modify or delete records, or execute administrative operations. The lack of input validation and parameterized queries makes it easier for attackers to craft malicious payloads.

Compliance Impact

This vulnerability can lead to unauthorized access to sensitive data, violating compliance requirements under GDPR and HIPAA. GDPR mandates strict data protection, while HIPAA requires safeguarding protected health information. Exploitation may result in data breaches, leading to legal penalties and reputational damage.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79573. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart