CVE-2026-2819 Details
Description
A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.5.3. This vulnerability affects the function SaServletFilter of the file /workflow/instance/deleteByInstanceIds of the component Workflow Module. The manipulation leads to missing authorization. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability exists in Dromara RuoYi-Vue-Plus versions through 5.5.3, specifically within the Workflow Module. The issue arises in the SaServletFilter function of the deleteByInstanceIds endpoint, where the application fails to enforce proper authorization checks. This flaw allows authenticated users with low privileges to bypass access controls and perform sensitive actions, such as deleting process instances, terminating tasks, and changing task assignees, by directly using the affected API. The vulnerability can be exploited remotely, and a public exploit is available.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 20, 2026CISA-ADP
Assessed Feb 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vuldb.com/?ctiid.346944 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.346944 | [email protected] | AdvisoryExploitTechnical Description |
| https://vuldb.com/?submit.753321 | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Dromara RuoYi-Vue-Plus | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Feb 20, 2026 | New CVE Received | [email protected] |
Volerion