CVE-2026-57949

MEDIUM

ruoyi-vue-pro - Missing Authorization in CRM Follow-up Record GET Endpoint

Title source: cna
STIX 2.1

Description

ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module's GET /admin-api/crm/follow-up-record/get endpoint that allows authenticated users to read any follow-up record by iterating sequential numeric IDs. Attackers can exploit this by sending requests with arbitrary ID parameters to access other users' follow-up notes, file attachments, scheduling information, and business entity references without proper authorization checks.

Scores

CVSS v3 6.5
EPSS 0.0023
EPSS Percentile 14.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
Yunai/ruoyi-vue-pro < 2026.05
Yunai/ruoyi-vue-pro c779a476617c58a38904191094d22df254b42542
Published Jun 29, 2026
Tracked Since Jun 29, 2026