CVE-2026-2107: yeqifu warehouse Log Info LoginfoController.java batchDeleteLoginfo improper authorization
A vulnerability was found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function loadAllLoginfo/deleteLoginfo/batchDeleteLoginfo of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\LoginfoController.java of the component Log Info Handler. The manipulation results in improper authorization. The attack can be launched remotely. The exploit has been made public and could be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2107?
CVE-2026-2107 has been classified with a critical severity due to improper authorization vulnerabilities that could lead to unauthorized access to logging functionalities.
How do I fix CVE-2026-2107?
To fix CVE-2026-2107, upgrade the yeqifu warehouse application to a version after commit aaf29962ba407d22d991781de28796ee7b4670e4.
What impact does CVE-2026-2107 have on the yeqifu warehouse?
CVE-2026-2107 allows unauthorized users to access and manipulate log information, potentially compromising system integrity and data confidentiality.
Who is affected by CVE-2026-2107?
CVE-2026-2107 affects all users of yeqifu warehouse versions prior to aaf29962ba407d22d991781de28796ee7b4670e4.
What components are involved in CVE-2026-2107?
CVE-2026-2107 involves the LoginfoController.java, specifically the functions loadAllLoginfo, deleteLoginfo, and batchDeleteLoginfo.