boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-95829

TDuckCloud tduck-platform Pagination Inner Interceptor MybatisPlusConfig.java PaginationInnerInterceptor.concatOrderBy sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0019    8.0     —
AFFECTED
  Product         Versions  Fixed
  tduck-platform  5.0 –     —
TIMELINE
  Sep 22  Reserved by VulDB
  Sep 22  Published (CNA: VulDB)
  Sep 23  RESCORED — CVE-2026-95829 (TDuckCloud tduck-platform). CVSS 5.3 → 2.1 (NVD).
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred

Description

A vulnerability was identified in TDuckCloud tduck-platform up to 5.3. This vulnerability affects the function PaginationInnerInterceptor.concatOrderBy of the file tduck-api/src/main/java/com/tduck/cloud/api/config/MybatisPlusConfig.java of the component Pagination Inner Interceptor. The manipulation of the argument orders[0].column leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used. The identifier of the patch is ea7f0fae7cb0fd998a3284c11addce689350cd69. It is suggested to install a patch to address this issue.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
September 22, 2026ReservedReserved by VulDB
September 22, 2026PublishedPublished (CNA: VulDB)
September 23, 2026RESCOREDRESCORED — CVE-2026-95829 (TDuckCloud tduck-platform). CVSS 5.3 → 2.1 (NVD).

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
TDuckCloudtduck-platform—5.0—

Weaknesses

CWE-74 · CWE-89

References (5)

Related

Authoritative record: CVE-2026-95829 at cve.org

Vendors: tduckcloud

Weaknesses: CWE-74 · CWE-89

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-95829 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.