A vulnerability was found in linlinjava litemall up to 1.8.0 and classified as critical . Affected is an unknown function of the component Admin Endpoint . Executing a manipulation can lead to sql injection. This vulnerability is handled as CVE-2026-8772 . The attack can be executed remotely. Additionally, an exploit exists. Multiple endpoints are affected. The vendor was contacted early about this disclosure but did not respond in any way.