References https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC%E6%8E%A5%E5%8F%A3ConfigResourceServlet%E5%AD%98%E5%9C%A8%E5%8F%8D%E5%BA%8F%E5%88%97%E6%BC%8F%E6%B4%9E.md https://hackeyes.github.io/2021/04/16/%E7%94%A8%E5%8F%8BNC%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E/ https://wiki.96.mk/Web%E5%AE%89%E5%85%A8/%E7%94%A8%E5%8F%8Bnc/%E7%94%A8%E5%8F%8Bnc%206.5%20%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E/ https://www.cnblogs.com/yysfa/p/17414084.html https://blog.nsfocus.net/nc/ https://github.com/bmth666/Yongyou-Unserialize-plus https://mrxn.net/jswz/yonyou-nc-ContactsQueryServiceServlet-rce.html https://cn-sec.com/archives/5125329.html https://jeyiuwai.pages.dev/posts/0-day-%E6%8C%96%E6%8E%98%E7%94%A8%E5%8F%8B-nc-modelhandleservlet-%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E/ https://github.com/tzwlhack/Vulnerability/blob/main/%E7%94%A8%E5%8F%8BNC%206.5%20%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C.md
Related VulnerabilitiesPoCCVE-2026-21589: Atlassian Jira/Confluence/Bitbucket - Pre-Auth Arbitrary File ReadPoCCVE-2026-29058: WWBN AVideo Encoder < 7.0 - Unauthenticated OS Command InjectionPoC用友NC /ebvp/infopub/showcontent SQL 注入漏洞PoCCVE-2026-58467: Cockpit CMS <= 2.14.0 - Path Traversal / Local File Inclusion关于NC系统的文件控制台SQL注入漏洞的安全通告PoCCVE-2026-9103: Langflow OSS - Superuser Token IssuancePoCCVE-2026-18072: Advanced Responsive Video Embedder 10.8.7/10.8.8 - Hardcoded Backdoor Authentication BypassPoCCVE-2026-27960: OpenCTI < 6.9.13 - Authentication Bypass via User ImpersonationPoCarangodb-auth-bypass: ArangoDB - Authentication Bypass via URL-Encoded Underscore (%5f) to RCEPoCCVE-2026-19092: Tutor LMS < 4.0.6 - Unauthenticated Arbitrary PHP Function InvocationPoCCVE-2026-29962: HSC MailInspector - Local File InclusionPoCCVE-2026-85200: GEO my WP <=4.5.5.3 - Unauthenticated Local File Inclusion華擎科技|ASRock Polychrome SYNC/RGB software utility - 存在2個漏洞