CVE-2026-2078 | yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4 Permission Management PermissionController.java addPermission/updatePermission/deletePermission improper authorization (Issue 55)
A vulnerability was found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. It has been classified as critical. This affects the function addPermission/updatePermission/deletePermission of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\PermissionController.java of the component Permission Management. Performing a manipulation results in improper authorization.
This vulnerability was named CVE-2026-2078. The attack may be initiated remotely. In addition, an exploit is available.
This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available.
The project was informed of the problem early through an issue report but has not responded yet.