CVE-2026-97324 | YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08 Demo-order Payment Callback PayDemoOrderController.java updateDemoOrderPaid ID improper authorization

SecurityVulns

A vulnerability classified as critical has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoOrderPaid of the file yudao-module-pay/src/main/java/cn/iocoder/yudao/module/pay/controller/admin/demo/PayDemoOrderController.java of the component Demo-order Payment Callback Handler. The manipulation of the argument ID leads to improper authorization.

This vulnerability is documented as CVE-2026-97324. The attack can be initiated remotely. Additionally, an exploit exists.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More