CVE-2026-92461: yshop-crm through 2.1.3 Missing Authorization via CRM Approval-Chain Endpoint
yshop-crm through 2.1.3 contains a missing authorization vulnerability in the GET /admin-api/crm/flow/flow-users endpoint that allows any logged-in back-office user to access approval workflow data. Attackers can retrieve approval chain topology, step ordering, approver identifiers, and personal information including login names, nicknames, departments, email addresses, mobile numbers and last login IP addresses.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated back-office user can access the affected endpoint; administrator or approval-workflow privileges are not required. Exploitation requires network access to the application and a valid logged-in back-office account.
What information can be exposed?
The endpoint can disclose approval-chain topology and step ordering, approver identifiers, and personal data including login names, nicknames, departments, email addresses, mobile numbers, and last-login IP addresses.
How can I determine whether my deployment is affected?
Deployments of yshop-crm through 2.1.3 should be considered affected if a non-privileged logged-in back-office user can request GET /admin-api/crm/flow/flow-users and receive approval workflow or user data.