CVE-2026-77795 | Dromara RuoYi-Vue-Plus up to 5.6.2 Workflow Endpoint improper authorization

SecurityVulns

A vulnerability described as critical has been identified in Dromara RuoYi-Vue-Plus up to 5.6.2. This issue affects the function FlwInstanceController/FlwDefinitionController/FlwCategoryController/FlwSpelController/TestLeaveController of the component Workflow Endpoint. Such manipulation leads to improper authorization.

This vulnerability is uniquely identified as CVE-2026-77795. The attack can be launched remotely. No exploit exists.VulDB Recent EntriesRead More