CVE-2025-70985
CRITICALRuoyi - Improper Access Control
Title source: ruleDescription
Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside of their scope.
Exploits (1)
Scores
CVSS v3
9.1
EPSS
0.0002
EPSS Percentile
5.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Details
CWE
CWE-284
CWE-862
Status
published
Products (2)
ruoyi/ruoyi
4.8.1
ruoyi/ruoyi
4.8.2
Published
Jan 23, 2026
Tracked Since
Feb 18, 2026