Yunaiv · Yudao-Cloud · CVE-2026-5148
**Name of the Vulnerable Software and Affected Versions**
YunaiV yudao-cloud versions prior to 2026.01
**Description**
A weakness exists in YunaiV yudao-cloud. This issue involves the manipulation of the `toMail` argument within the file `/admin-api/system/mail-log/page`, leading to a SQL injection. The attack can be initiated remotely. The exploit has been made publicly available. The vendor was contacted regarding this disclosure but did not respond.
**Recommendations**
Versions prior to 2026.01: At the moment, there is no information about a newer version that contains a fix for this vulnerability.