CVE-2026-2106: yeqifu warehouse Notice Management NoticeController.java batchDeleteNotice improper authorization
A vulnerability has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. The impacted element is the function addNotice/updateNotice/deleteNotice/batchDeleteNotice of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\NoticeController.java of the component Notice Management. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2106?
CVE-2026-2106 has a medium severity due to improper authorization in several notice management functions.
How do I fix CVE-2026-2106?
To fix CVE-2026-2106, ensure proper access controls and authorization checks are implemented in the addNotice, updateNotice, deleteNotice, and batchDeleteNotice functions.
Which versions of yeqifu warehouse are affected by CVE-2026-2106?
CVE-2026-2106 affects yeqifu warehouse up to version aaf29962ba407d22d991781de28796ee7b4670e4.
What functions are impacted by CVE-2026-2106?
CVE-2026-2106 impacts the functions addNotice, updateNotice, deleteNotice, and batchDeleteNotice.
Can CVE-2026-2106 lead to unauthorized access?
Yes, CVE-2026-2106 can lead to unauthorized access due to improper authorization mechanisms in the warehouse notice management.