VYPR

ruoyi-workflow

by RuoYi Cloud Plus

CVEs (1)

  • CVE-2026-71807Sep 9, 2026
    risk 0.00cvss epss

    In RuoYi-Cloud-Plus <= 2.6.2 in the ruoyi-workflow module, multiple core task APIs in FlwTaskController lack permission annotations, and the Service layer does not verify whether the current user is the task handler/related user. Authenticated low-privileged remote attackers can…