CVE-2026-2076: yeqifu warehouse User Management Endpoint UserController.java deleteUser improper authorization
A weakness has been identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this vulnerability is the function addUser/updateUser/deleteUser of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\UserController.java of the component User Management Endpoint. This manipulation causes improper authorization. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2076?
CVE-2026-2076 has been classified with a medium severity level due to improper authorization in user management functions.
How do I fix CVE-2026-2076?
To fix CVE-2026-2076, update yeqifu warehouse to a version beyond aaf29962ba407d22d991781de28796ee7b4670e4.
What functionality is affected by CVE-2026-2076?
CVE-2026-2076 affects the addUser, updateUser, and deleteUser functions in the UserController.java file.
What is the impact of CVE-2026-2076?
The impact of CVE-2026-2076 is that unauthorized users may gain access to user management operations.
Is there a workaround for CVE-2026-2076?
While no official workaround is recommended, limiting access to the affected user management endpoints can reduce exposure until a patch is applied.