CVE-2025-56396: High severity Ruoyi Ruoyi vulnerability
Published Nov 26, 2025
·Updated
An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department having higher rights than the active user.
Affected Software
2 affected components
Ruoyi Ruoyi
Ruoyi Ruoyi=4.8.1
Event History
Nov 26, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-56396?
CVE-2025-56396 has a high severity rating due to its potential for privilege escalation.
2
How do I fix CVE-2025-56396?
To fix CVE-2025-56396, it is recommended to update Ruoyi to the latest version where this vulnerability is patched.
3
Who is affected by CVE-2025-56396?
CVE-2025-56396 affects users of Ruoyi version 4.8.1 who may have insufficient access controls.
4
What type of vulnerability is CVE-2025-56396?
CVE-2025-56396 is a privilege escalation vulnerability.
5
What systems are vulnerable to CVE-2025-56396?
Systems running Ruoyi version 4.8.1 are vulnerable to CVE-2025-56396.