CVE-2025-70986
HIGHRuoyi - Improper Access Control
Title source: ruleDescription
Incorrect access control in the selectDept function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily access sensitive department data.
Exploits (1)
Scores
CVSS v3
7.5
EPSS
0.0002
EPSS Percentile
5.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-284
CWE-862
Status
published
Products (2)
ruoyi/ruoyi
4.8.1
ruoyi/ruoyi
4.8.2
Published
Jan 23, 2026
Tracked Since
Feb 18, 2026