CVE-2026-77036: elunez eladmin GenConfigController improper authorization
A vulnerability was found in elunez eladmin up to 2.7. The impacted element is the function EmailController/AliPayController/GeneratorController/GenConfigController. The manipulation results in improper authorization. The attack can be launched remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
elunez eladminto a version that resolves this vulnerability.Fixed in 2.7 - Compensating control
Restrict remote access to the affected elunez eladmin controllers (EmailController/AliPayController/GeneratorController/GenConfigController) at the network layer (e.g., firewall/ACL) to reduce exposure until a fixed version is applied.
Event History
Frequently Asked Questions
What level of access does an attacker need?
The CVSS vector indicates that exploitation is network-reachable and requires low-level privileges. No user interaction is required.
Which components should be reviewed in potentially affected deployments?
The reported affected functionality includes EmailController, AliPayController, GeneratorController, and GenConfigController in eladmin versions up to 2.7.
How urgent is remediation or exposure reduction?
A public exploit has been reported, and the vulnerability has a medium CVSS score of 6.3 with impacts to confidentiality, integrity, and availability. The project was notified through an issue report but had not responded at the time of publication.