Improper Authentication Vulnerability in YunaiV yudao-cloud
CVE-2026-7679
Key Information:
- Vendor
Yunaiv
- Status
- Vendor
- CVE Published:
- 3 May 2026
Badges
What is CVE-2026-7679?
A security flaw has been discovered in YunaiV's yudao-cloud that affects the getAccessToken function within the OAuth2TokenServiceImpl.java located at yudao-module-system-biz/src/main/java/io/github/ruoyi/common/oauth2/service/impl. This vulnerability allows for improper authentication, which can be exploited remotely. An attack can be initiated by manipulating the function, leading to unauthorized access. Publicly available exploit code raises concerns regarding the risk it poses, especially since the vendor has not responded to previous disclosures regarding this issue.
Affected Version(s)
yudao-cloud 2026.01
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
