CVE-2026-2078 - yeqifu warehouse Permission Management PermissionController.java deletePermission...

CVE-2026-2078 - yeqifu warehouse Permission Management PermissionController.java deletePermission...

CVE ID : CVE-2026-2078 Published : Feb. 7, 2026, 8:15 a.m. | 53 minutes ago Description : A vulnerability was detected in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function addPermission/updatePermission/deletePermission of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\PermissionController.java of the component Permission Management. Performing a manipulation results in improper authorization. The attack may be initiated remotely. The exploit is now public and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Feb. 7, 2026
Affected Product: java