ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 contains a broken access control vulnerability in ErpSaleOrderController that allows attackers with erp:sale-out permissions to gain unauthorized access to sale order operations by exploiting an incorrect permission namespace enforcement. Attackers holding shipment-level permissions can perform unauthorized create, update, delete, and read operations on financially sensitive sale orders due to the controller enforcing erp:sale-out instead of the intended erp:sale-order namespace.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-06-29 18:16
Updated : 2026-07-14 22:17
NVD link : CVE-2026-57950
Mitre link : CVE-2026-57950
CVE.ORG link : CVE-2026-57950
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
