Improper Authorization in YeQifu Warehouse Notice Management System
CVE-2026-2106
Key Information:
Badges
What is CVE-2026-2106?
A vulnerability exists in the YeQifu Warehouse's Notice Management component, specifically within the functions addNotice, updateNotice, deleteNotice, and batchDeleteNotice found in NoticeController.java. This flaw allows for improper authorization, enabling remote attackers to exploit the system without proper user credentials. Despite the issue being reported early, the project has yet to address the problem or release an updated version. Continuous delivery practices complicate the tracking of affected releases, leaving users at potential risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
warehouse aaf29962ba407d22d991781de28796ee7b4670e4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
