Authorization Bypass in RuoYi-Vue-Plus Workflow Management
CVE-2026-58176
Key Information:
- Vendor
Dromara
- Status
- Vendor
- CVE Published:
- 30 June 2026
Badges
What is CVE-2026-58176?
RuoYi-Vue-Plus versions up to 5.6.2 have a significant security flaw where workflow task management endpoints lack proper authorization checks. This vulnerability allows any authenticated user, regardless of their role, to manipulate task assignments, circumventing the intended separation of duties in approval workflows. Specifically, users can reassign approval tasks to any user, trigger arbitrary tasks, and view both pending and completed tasks through specific listing endpoints. The issue has been addressed by implementing necessary permission checks to secure these endpoints.
Affected Version(s)
RuoYi-Vue-Plus 0 <= 5.6.2
RuoYi-Vue-Plus 88d03d970d4d1e96e4fb2dfefaf19f627e8673e9
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
