CVE-2026-2077: yeqifu warehouse Role Management RoleController.java deleteRole improper authorization
A security vulnerability has been detected in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this issue is the function addRole/updateRole/deleteRole of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\RoleController.java of the component Role Management Handler. Such manipulation leads to improper authorization. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2077?
CVE-2026-2077 has been classified as a security vulnerability due to improper authorization in role management.
How do I fix CVE-2026-2077?
To mitigate CVE-2026-2077, update the yeqifu warehouse software to a version after aaf29962ba407d22d991781de28796ee7b4670e4.
What functions are affected by CVE-2026-2077?
CVE-2026-2077 affects the addRole, updateRole, and deleteRole functions within the RoleController.java file.
What happens if I do not address CVE-2026-2077?
Failure to address CVE-2026-2077 could lead to unauthorized access and manipulation of role management within the yeqifu warehouse.
Which versions of yeqifu warehouse are vulnerable to CVE-2026-2077?
Versions of yeqifu warehouse up to and including aaf29962ba407d22d991781de28796ee7b4670e4 are affected by CVE-2026-2077.