ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 contains a broken access control vulnerability in ErpSaleOrderController that allows attackers with erp:sale-out permissions to gain unauthorized access to sale order operations by exploiting an incorrect permission namespace enforcement. Attackers holding shipment-level permissions can perform unauthorized create, update, delete, and read operations on financially sensitive sale orders due to the controller enforcing erp:sale-out instead of the intended erp:sale-order namespace.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57950.json",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"last_affected": "2026.05"
}
]
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "2026.05"
}
]
},
{
"source": "DESCRIPTION",
"extracted_events": [
{
"fixed": "2026.05"
}
]
}
],
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-863"
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-57950.json"
"2026-07-22T03:45:02Z"
[
{
"target": {
"file": "yudao-module-erp/src/main/java/cn/iocoder/yudao/module/erp/controller/admin/sale/ErpSaleOrderController.java"
},
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2026-57950-d7b0fd03",
"signature_version": "v1",
"source": "https://github.com/yunaiv/ruoyi-vue-pro/commit/5d1fd70dc3e61bf64e7ce3328a71cc60001175c6",
"digest": {
"line_hashes": [
"155641830515662629309437308700315800726",
"304690355565161061612785979169697802004",
"278723312396524036702560338690644516145",
"234311791846720786701174264175639560108",
"203694783014231558713613711855502211466",
"55612295600540338000873379934430800526",
"247696564015289663302137966120977772084",
"269606027244595265793518656155228669833",
"17326808011812700303067090574806787342",
"303788751733898165659680654444237241923",
"134347734479933573030936174227969618180",
"288827495588954998051284887833232997980",
"201959010410460573515819774263125419859",
"79070453393838198590525226851494743375",
"6465610140179086049042578630441243540",
"249863667103703137508344500622238906302",
"314413593916576850520040365311436661359",
"196704685146698596502196935364201308484",
"289326667563294517516833445557416733916",
"67363482816466310710996747380035787833",
"277626208753794354252659551241968014069",
"205670871840921159278249680932557962302",
"102505923198359814155534088408796057866",
"88443917583060182809229393106491373566",
"59792755461335421375044847236216066681",
"171966656399997897912873585780516359051",
"232177977511494339261724249375960551884",
"240758112645152397815524068355776979248",
"50039593450781217747570360654480857713",
"53913400821180526528745575402851050514",
"211527384108424423114405783028976183772"
],
"threshold": 0.9
}
}
]