PT-2026-6876 · Unknown · Yeqifu Warehouse
Alices614
·
Published
2026-02-07
·
Updated
2026-02-07
·
CVE-2026-2075
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
yeqifu warehouse versions prior to aaf29962ba407d22d991781de28796ee7b4670e4
Description
A security flaw exists due to improper access controls. The issue is located in the
saveRolePermission function within the file datasetreposwarehousesrcmainjavacomyeqifusyscontrollerRoleController.java of the Role-Permission Binding Handler component. This flaw allows for remote attacks, and an exploit has been publicly released. The project has been notified but has not yet responded.Recommendations
Update to version aaf29962ba407d22d991781de28796ee7b4670e4 or later.
Exploit
Fix
Improper Access Control
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Yeqifu Warehouse