CVE-2025-56396

HIGH

Ruoyi - Improper Access Control

Title source: rule

Description

An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department having higher rights than the active user.

Exploits (1)

gitee 47,892 stars
by y_project · javawriteup
https://gitee.com/y_project/RuoYi/issues/ICJ865

Scores

CVSS v3 8.8
EPSS 0.0006
EPSS Percentile 17.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-284
Status published
Products (1)
ruoyi/ruoyi 4.8.1
Published Nov 26, 2025
Tracked Since Feb 18, 2026