High severity7.5NVD Advisory· Published Dec 22, 2025· Updated Jun 17, 2026
CVE-2025-66735
CVE-2025-66735
Description
youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The getRoleForm function in SysRoleController.java does not perform permission checks, which may allow non-root users to directly access root roles.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- youlai-boot/youlai-bootdescription
- Range: = 2.21.1
- cpe:2.3:a:youlai:youlai-boot:2.21.1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- gitee.com/youlaiorg/youlai-boot/commit/9197065102f92264ded814a9d3e9f2a4ff0da121nvdPatch
- gitee.com/youlaiorg/youlai-boot/issues/ICH8FRnvdExploitIssue TrackingVendor Advisory
- gist.github.com/old6ma/dc9e6e4a693d12c1a35fd4e1d21d4743nvdThird Party Advisory
News mentions
0No linked articles in our index yet.