PT-2026-20990 · Dromara · Ruoyi-Vue-Plus
Feng123123
·
Published
2026-02-20
·
Updated
2026-02-20
·
CVE-2026-2819
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Dromara RuoYi-Vue-Plus versions through 5.5.3
Description
A missing authorization issue exists in the Workflow Module of Dromara RuoYi-Vue-Plus. The issue affects the
SaServletFilter function within the /workflow/instance/deleteByInstanceIds file. This allows for remote exploitation due to a lack of proper authorization checks. The exploit is publicly available.Recommendations
Update to a version beyond 5.5.3. As a temporary workaround, restrict access to the
/workflow/instance/deleteByInstanceIds file and the SaServletFilter function.Fix
Missing Authorization
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ruoyi-Vue-Plus