Description
Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialized payload via POST request. Attackers can exploit the doAction method, which passes raw HTTP request body data directly to ObjectInputStream.readObject() without filtering, to achieve remote code execution. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-02-13.
Published: 2026-09-15
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Yonyou U8 Cloud contains an unauthenticated Java deserialization flaw in the FileManageServlet component. Attackers can send a crafted POST request that is read directly by ObjectInputStream.readObject(), allowing arbitrary OS command execution. The vulnerability bypasses authentication and permits full control of the affected server, compromising confidentiality, integrity, and availability. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-02-13.

Affected Systems

The vulnerability affects the Yonyou U8 Cloud product offered by Yonyou. No specific version is indicated in the CNA data, so all deployed instances of Yonyou U8 Cloud, regardless of patch level, may be susceptible unless they have applied the vendor's patch.

Risk and Exploitability

The CVSS score for this vulnerability is 9.3, indicating critical severity and a high potential impact. The EPSS score is < 1%, suggesting a very low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog, but that does not diminish its risk. Attackers can exploit the unfiltered ObjectInputStream.readObject() call by sending a crafted POST request to the FileManageServlet endpoint over the network, bypassing authentication and enabling remote command execution. The lack of authentication and the direct deserialization make the attack vector straightforward and highly plausible for a motivated adversary.

Generated by OpenCVE AI on September 20, 2026 at 15:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor’s latest patch that fixes the FileManageServlet deserialization issue promptly.
  • Restrict or block unauthenticated access to the /FileManageServlet endpoint using firewall or web-application firewall rules.
  • Remove or replace the vulnerable ObjectInputStream usage with a safe deserialization mechanism or input validation to prevent arbitrary object deserialization.

Generated by OpenCVE AI on September 20, 2026 at 15:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Yonyou
Yonyou u8 Cloud
Vendors & Products Yonyou
Yonyou u8 Cloud

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialized payload via POST request. Attackers can exploit the doAction method, which passes raw HTTP request body data directly to ObjectInputStream.readObject() without filtering, to achieve remote code execution. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-02-13.
Title Yonyou U8 Cloud Java Deserialization RCE via FileManageServlet
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T17:30:23.072Z

Reserved: 2026-09-15T16:26:30.768Z

Link: CVE-2023-54398

cve-icon Vulnrichment

Updated: 2026-09-15T17:30:19.178Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T17:17:08.343

Modified: 2026-09-24T20:43:32.537

Link: CVE-2023-54398

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:30:17Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data