Improper Access Controls in Customer Endpoint of yeqifu Warehouse
CVE-2026-2850
Key Information:
Badges
What is CVE-2026-2850?
A vulnerability was identified in the yeqifu warehouse affecting the Customer Endpoint's addCustomer, updateCustomer, and deleteCustomer functions. This flaw leads to improper access controls, allowing for potential remote exploitation. The vulnerability was made public, and while it has been acknowledged through issue reports, the project maintainers have not yet provided a response or patch. The product follows a rolling release model, making specific version details for affected or updated releases unavailable. Users are advised to take immediate precautions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
warehouse aaf29962ba407d22d991781de28796ee7b4670e4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
