CVE-2026-7679: YunaiV yudao-cloud OAuth2TokenServiceImpl.java getAccessToken improper authentication
A security flaw has been discovered in YunaiV yudao-cloud up to 2026.01. This impacts the function getAccessToken of the file yudao-module-system-biz/src/main/java/io/github/ruoyi/common/oauth2/service/impl/OAuth2TokenServiceImpl.java. Performing a manipulation results in improper authentication. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7679?
CVE-2026-7679 is considered a significant vulnerability due to improper authentication in the getAccessToken function.
How do I fix CVE-2026-7679?
To fix CVE-2026-7679, upgrade to a version of YunaiV yudao-cloud newer than 2026.01 that addresses this vulnerability.
What impact does CVE-2026-7679 have on my system?
CVE-2026-7679 can lead to unauthorized access to tokens, potentially allowing attackers to impersonate users.
Is CVE-2026-7679 being actively exploited?
There are no public reports indicating that CVE-2026-7679 is actively being exploited in the wild.
Which versions of YunaiV yudao-cloud are affected by CVE-2026-7679?
CVE-2026-7679 affects all versions of YunaiV yudao-cloud up to and including 2026.01.