CVE-2026-2850 Details
Description
A vulnerability was found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function addCustomer/updateCustomer/deleteCustomer of the file dataset\repos\warehouse\src\main\java\com\yeqifu\bus\controller\CustomerController.java of the component Customer Endpoint. Performing a manipulation results in improper access controls. Remote exploitation of the attack is possible. The exploit has been made public and could be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability exists in Yeqifu Warehouse versions up to commit aaf29962ba407d22d991781de28796ee7b4670e4, specifically within the Customer Endpoint. The issue arises in the CustomerController.java file, affecting the addCustomer, updateCustomer, and deleteCustomer functions. This vulnerability allows logged-in users to manipulate core business data by adding, updating, or deleting customer information without proper authorization. As a result, it could lead to unauthorized changes, fraudulent records, and potential disruptions in business operations. The vulnerability can be exploited remotely, and a public exploit is available.
It is recommended to implement proper role-based access controls for the affected endpoints, ensuring that only authorized users can perform add, update, or delete actions. Validation of ownership should be included where applicable.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/yeqifu/warehouse/ | [email protected] | Product |
| https://github.com/yeqifu/warehouse/issues/61 | [email protected] | ExploitIssue TrackingVendor Advisory |
| https://github.com/yeqifu/warehouse/issues/61#issue-3846669982 | [email protected] | ExploitIssue Tracking |
| https://vuldb.com/?ctiid.347086 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.347086 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.754429 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| yeqifu warehouse | <= 2025-10-06 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Feb 26, 2026 | Initial Analysis | [email protected] |
| Feb 20, 2026 | New CVE Received | [email protected] |