CVE-2026-57950

Source
https://cve.org/CVERecord?id=CVE-2026-57950
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-57950.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-57950
Published
2026-06-29T17:20:07.371Z
Modified
2026-07-22T03:45:02.560029Z
Severity
  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
ruoyi-vue-pro - Incorrect Permission Namespace in ErpSaleOrderController
Details

ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 contains a broken access control vulnerability in ErpSaleOrderController that allows attackers with erp:sale-out permissions to gain unauthorized access to sale order operations by exploiting an incorrect permission namespace enforcement. Attackers holding shipment-level permissions can perform unauthorized create, update, delete, and read operations on financially sensitive sale orders due to the controller enforcing erp:sale-out instead of the intended erp:sale-order namespace.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57950.json",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "last_affected": "2026.05"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "extracted_events": [
                {
                    "last_affected": "2026.05"
                }
            ]
        },
        {
            "source": "DESCRIPTION",
            "extracted_events": [
                {
                    "fixed": "2026.05"
                }
            ]
        }
    ],
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-863"
    ]
}
References

Affected packages

Git / github.com/yunaiv/ruoyi-vue-pro

Affected ranges

Type
GIT
Repo
https://github.com/yunaiv/ruoyi-vue-pro
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "REFERENCES"
}

Affected versions

v1.*
v1.0.0
v1.1.0
v1.2.0
v1.3.0
v1.4.0
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.6.5
v1.6.6
v1.7.0
v1.7.1
v1.7.2
v1.7.3
v1.8.0
v2.*
v2.2.0(jdk17/21)
v2.3.0(jdk17/21)
v2.4.0(jdk17/21)
v2.4.1(jdk17/21)
v2.4.1(jdk8/11)
v2.4.2(jdk17/21)
v2.5.0(jdk17/21)
v2.5.0(jdk8/11)
v2.6.0(jdk17/21)
v2.6.1(jdk17/21)
v2025.*
v2025.08(jdk17/21)
v2025.10(jdk17/21)
v2025.11(jdk17/21)
v2025.12(jdk17/21)
v2026.*
v2026.01(jdk17/21)
v2026.03(jdk17/21)
v2026.04(jdk17/21)
v2026.05(jdk17/21)

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-57950.json"
vanir_signatures_modified
"2026-07-22T03:45:02Z"
vanir_signatures
[
    {
        "target": {
            "file": "yudao-module-erp/src/main/java/cn/iocoder/yudao/module/erp/controller/admin/sale/ErpSaleOrderController.java"
        },
        "deprecated": false,
        "signature_type": "Line",
        "id": "CVE-2026-57950-d7b0fd03",
        "signature_version": "v1",
        "source": "https://github.com/yunaiv/ruoyi-vue-pro/commit/5d1fd70dc3e61bf64e7ce3328a71cc60001175c6",
        "digest": {
            "line_hashes": [
                "155641830515662629309437308700315800726",
                "304690355565161061612785979169697802004",
                "278723312396524036702560338690644516145",
                "234311791846720786701174264175639560108",
                "203694783014231558713613711855502211466",
                "55612295600540338000873379934430800526",
                "247696564015289663302137966120977772084",
                "269606027244595265793518656155228669833",
                "17326808011812700303067090574806787342",
                "303788751733898165659680654444237241923",
                "134347734479933573030936174227969618180",
                "288827495588954998051284887833232997980",
                "201959010410460573515819774263125419859",
                "79070453393838198590525226851494743375",
                "6465610140179086049042578630441243540",
                "249863667103703137508344500622238906302",
                "314413593916576850520040365311436661359",
                "196704685146698596502196935364201308484",
                "289326667563294517516833445557416733916",
                "67363482816466310710996747380035787833",
                "277626208753794354252659551241968014069",
                "205670871840921159278249680932557962302",
                "102505923198359814155534088408796057866",
                "88443917583060182809229393106491373566",
                "59792755461335421375044847236216066681",
                "171966656399997897912873585780516359051",
                "232177977511494339261724249375960551884",
                "240758112645152397815524068355776979248",
                "50039593450781217747570360654480857713",
                "53913400821180526528745575402851050514",
                "211527384108424423114405783028976183772"
            ],
            "threshold": 0.9
        }
    }
]