Access Control Vulnerability in RuoYi v4.8.2 by Yangzongzhuan
CVE-2025-70986

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
23 January 2026

What is CVE-2025-70986?

A security flaw exists in the selectDept function of RuoYi v4.8.2, enabling unauthorized attackers to bypass access controls and gain access to sensitive department data. This vulnerability poses a significant risk, as it can lead to data leaks and compromise overall system integrity. It is crucial for users and administrators of RuoYi to apply necessary security measures and updates to safeguard against potential exploitation. For more information, you can refer to the official repositories and discussions available on GitHub and Gitee.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.