CVE-2026-2549

Source
https://cve.org/CVERecord?id=CVE-2026-2549
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-2549.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-2549
Published
2026-02-16T09:32:06.062Z
Modified
2026-07-15T01:49:14.309752762Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
zhanghuanhao LibrarySystem 图书馆管理系统 BookController.java access control
Details

A vulnerability has been found in zhanghuanhao LibrarySystem 图书馆管理系统 up to 1.1.1. This impacts an unknown function of the file BookController.java. The manipulation leads to improper access controls. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2549.json",
    "cwe_ids": [
        "CWE-266",
        "CWE-284"
    ],
    "cna_assigner": "VulDB",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "1.1.0"
                },
                {
                    "last_affected": "1.1.0"
                }
            ]
        }
    ]
}
References

Affected packages

Git / github.com/zhanghuanhao/librarysystem

Affected ranges

Type
GIT
Repo
https://github.com/zhanghuanhao/librarysystem
Events
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "1.1.1"
        },
        {
            "last_affected": "1.1.1"
        }
    ]
}

Affected versions

1.*
1.1.1
v1.*
v1.1.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-2549.json"