Overview
GouGuOA is a Chinese office-automation (OA) web platform used by organizations to manage internal collaboration, messaging, approvals, and administrative workflows. A critical SQL injection vulnerability, tracked as CVE-2026-88395, has been disclosed in GouGuOA version 6.0.5 and earlier.
The flaw lives in the keywords parameter of the /home/message/rubbish endpoint, part of the platform's internal message/"trash" module. User-supplied input to keywords is concatenated directly into a SQL query without proper sanitization or parameterization, allowing an attacker to inject arbitrary SQL.
The vulnerability carries a CVSS score of 9.8 (Critical), reflecting a network-exploitable flaw with low attack complexity. Successful exploitation can expose the entire backend database for unauthenticated or minimally privileged read and write access — including administrator credentials — and, depending on the privileges and features exposed by the underlying database engine, could potentially be chained toward remote code execution.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-88395 |
| Severity | Critical (9.8) |
| CWE | CWE-89 (SQL Injection) |
| Attack Vector | Network |
| Authentication | None required (per published CVSS vector) |
| Privileges Required | None |
| User Interaction | None |
| Impact | High — Confidentiality, Integrity, and Availability (full database read/write) |
| Affected Versions | GouGuOA 6.0.5 and earlier |
| Fixed Version | Not yet published — verify against vendor release notes |
How It Works
The /home/message/rubbish endpoint's keywords parameter is concatenated into a raw SQL WHERE/LIKE clause and executed without parameter binding. Because the input is never escaped or passed through a prepared statement, an attacker can break out of the intended string context and inject arbitrary SQL logic.
Public technical write-ups describing this flaw demonstrate multiple exploitation techniques against the vulnerable endpoint, including:
- Boolean-based blind injection — crafting
keywordspayloads that alter query logic (true/false conditions) to infer database contents one bit at a time. - Error-based injection — using functions such as
EXTRACTVALUE()to force SQL/XPATH errors that leak database contents directly into the application's error response. - Time-based blind injection — using functions such as
SLEEP()to introduce measurable response delays, confirming the injection independent of error output or debug settings.
These techniques can be used to enumerate the active database name, table structures, and extract arbitrary table data — including administrator password hashes and salts stored in the OA database. Some published analysis of this endpoint also notes that the affected message controller is excluded from the application's normal privilege-check logic, which is consistent with the published CVSS vector rating the flaw as exploitable without any required privileges.
Beyond data theft, the impact could extend further: if the underlying database engine exposes command-execution features (for example, stacked-query support or engine-specific extensions), a SQL injection of this type could potentially be chained into operating-system command execution. No such RCE chain has been publicly demonstrated for this specific CVE as of this writing, but it remains a credible escalation path given the CVSS impact ratings (confidentiality, integrity, and availability all rated High).
Impact Assessment
Who Is At Risk
Any organization running an unpatched GouGuOA deployment is at risk, but the greatest exposure falls on internet-facing instances — OA platforms exposed directly to the public internet without compensating network controls. Given the low attack complexity and lack of required privileges, a publicly reachable vulnerable instance can be discovered and exploited with commodity scanning and injection tooling.
Potential Attack Chains
- Discovery — an attacker identifies a publicly reachable GouGuOA instance and the vulnerable
/home/message/rubbishendpoint. - Exploitation — a crafted
keywordspayload is submitted, using boolean-based, error-based, or time-based blind SQL injection techniques. - Data exfiltration — the attacker extracts database contents, including administrator password hashes/salts and other sensitive OA records.
- Lateral movement — harvested credentials are reused to access other OA modules, internal systems, or external services where the same credentials were reused.
Mitigation
Immediate Actions
- Patch or upgrade GouGuOA as soon as the vendor publishes a fixed release — confirm the actual fixed version against GouGuOA's official release notes, as none has been independently verified as of this writing.
- As a stopgap, deploy a WAF rule blocking common SQL injection patterns (quotes,
UNION,SLEEP(),EXTRACTVALUE(), comment sequences such as--or#) on requests to the/home/message/rubbishendpoint'skeywordsparameter, or restrict/disable access to the endpoint until patched. - Restrict external network access to the OA platform where internet exposure is not strictly required.
Detection Opportunities
- Review web server and application logs for anomalous
keywordsparameter values containing SQL syntax, boolean-logic patterns, or known injection functions (SLEEP,EXTRACTVALUE,UNION SELECT, SQL comment terminators). - Watch for unusual response-time variance on requests to
/home/message/rubbish, which may indicate time-based blind injection probing.
Defence-in-Depth
- Enforce least-privilege database accounts for the OA application so a compromised web-tier credential cannot read or write unrelated tables.
- Migrate the application's query layer to parameterized queries/prepared statements going forward, rather than raw string concatenation.
- Network-segment OA systems away from the public internet and from other critical internal systems to limit blast radius if the database is compromised.
Discovery & Disclosure
CVE-2026-88395 was reserved on 2026-09-10 and published via the NVD on 2026-10-05. The CVE record's technical reference points to a public write-up by GitHub user fangtang7, documenting the vulnerable endpoint and demonstrating working error-based and time-based injection techniques.
No named individual discoverer, vendor security advisory, or GHSA identifier was verifiable through public search as of this writing. There is no confirmed listing in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no publicly confirmed evidence of in-the-wild exploitation as of publication — though a working public proof-of-concept technique write-up does exist, which increases the likelihood of near-term exploitation attempts.