CVE-2026-57949: ruoyi-vue-pro - Missing Authorization in CRM Follow-up Record GET Endpoint
ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module's GET /admin-api/crm/follow-up-record/get endpoint that allows authenticated users to read any follow-up record by iterating sequential numeric IDs. Attackers can exploit this by sending requests with arbitrary ID parameters to access other users' follow-up notes, file attachments, scheduling information, and business entity references without proper authorization checks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ruoyi-vue-proto a version that resolves this vulnerability.Fixed in 2026.05Patch c779a47
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57949?
CVE-2026-57949 has a medium severity score of 6.5.
How do I fix CVE-2026-57949?
To fix CVE-2026-57949, update to the latest version of ruoyi-vue-pro that includes the patch from commit c779a47.
What impact does CVE-2026-57949 have on my application?
CVE-2026-57949 allows authenticated users to access follow-up records without proper authorization, potentially exposing sensitive information.
Who is affected by CVE-2026-57949?
Any application using ruoyi-vue-pro before the patch in commit c779a47 is at risk from CVE-2026-57949.
Can CVE-2026-57949 be exploited remotely?
Yes, CVE-2026-57949 can be exploited remotely by authenticated users exploiting the vulnerable GET endpoint.