A vulnerability was found in Jinher OA. It has been classified as critical. The affected element is an unknown function of the file sp_manager_getUserlist.aspx of the component GetXmlHttp. Performing a manipulation results in xml external entity reference.

This vulnerability is identified as CVE-2026-50782. The attack can be initiated remotely. There is not any exploit available.