CVE-2026-108825 | yangzongzhuan RuoYi up to 4.8.3 authDataScope checkRoleAllowed roleKey privileges management

SecurityVulns

A vulnerability, which was classified as problematic, was found in yangzongzhuan RuoYi up to 4.8.3. This affects the function checkRoleAllowed of the file /system/role/authDataScope. Such manipulation of the argument roleKey leads to improper privilege management.

This vulnerability is referenced as CVE-2026-108825. It is possible to launch the attack remotely. Furthermore, an exploit is available.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More