Authentication Flaw in Yuxi Knowledge Base Platform
CVE-2026-50561

9.4CRITICAL

Key Information:

Vendor

Xerrors

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-50561?

The Yuxi Knowledge Base platform has a security flaw in its authentication mechanism that allows an attacker to bypass normal login processes. This issue arises from insufficient validation of the identity token in the Authorization header. Consequently, an administrator token from a different deployment or a local testing environment can be misused to access backend management interfaces of another affected instance. An attacker in possession of a valid administrator Authorization token can gain unauthorized administrator privileges, enabling them to manipulate system configurations, invoke backend management APIs, create new administrator accounts, and potentially take full control of the backend. Users are urged to upgrade to version 0.6.2 to mitigate this issue and are advised to implement protective measures, such as setting a unique JWT_SECRET_KEY and restricting access to management interfaces.

Affected Version(s)

Yuxi < 0.6.2

References

CVSS V3.1

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.