CVE-2026-9374: yangzongzhuan RuoYi-Vue Common Upload Endpoint upload FileUploadUtils.upload unrestricted upload
A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.9.2. Impacted is the function FileUploadUtils.upload of the file /common/upload of the component Common Upload Endpoint. Performing a manipulation results in unrestricted upload. The attack is possible to be carried out remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9374?
The severity of CVE-2026-9374 is medium with a score of 6.3.
How do I fix CVE-2026-9374?
To fix CVE-2026-9374, ensure that file uploads are properly validated and restricted to prevent malicious file uploads.
What type of attack is associated with CVE-2026-9374?
CVE-2026-9374 is associated with remote attacks that exploit unrestricted file upload capabilities.
Which component is affected by CVE-2026-9374?
CVE-2026-9374 affects the Common Upload Endpoint in the yangzongzhuan RuoYi-Vue version up to 3.9.2.
When was CVE-2026-9374 published?
CVE-2026-9374 was published on May 24, 2026.