A vulnerability was detected in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function addPermission/updatePermission/deletePermission of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\PermissionController.java of the component Permission Management. Performing a manipulation results in improper authorization. The attack may be initiated remotely. The exploit is now public and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.
References
| Link | Resource |
|---|---|
| https://github.com/yeqifu/warehouse/ | Product |
| https://github.com/yeqifu/warehouse/issues/55 | Exploit Issue Tracking Vendor Advisory |
| https://github.com/yeqifu/warehouse/issues/55#issue-3846656775 | Exploit Issue Tracking Vendor Advisory |
| https://vuldb.com/?ctiid.344644 | Permissions Required VDB Entry |
| https://vuldb.com/?id.344644 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.745513 | Third Party Advisory VDB Entry |
Configurations
History
No history.
Information
Published : 2026-02-07 08:15
Updated : 2026-02-10 15:14
NVD link : CVE-2026-2078
Mitre link : CVE-2026-2078
CVE.ORG link : CVE-2026-2078
JSON object : View
Products Affected
yeqifu
- warehouse
