CVE-2026-57950 Details
Description
ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 contains a broken access control vulnerability in ErpSaleOrderController that allows attackers with erp:sale-out permissions to gain unauthorized access to sale order operations by exploiting an incorrect permission namespace enforcement. Attackers holding shipment-level permissions can perform unauthorized create, update, delete, and read operations on financially sensitive sale orders due to the controller enforcing erp:sale-out instead of the intended erp:sale-order namespace.
A broken access control vulnerability has been identified in the RuoYi Vue Pro ERP module, affecting versions through 2026.05. The issue arises in the ErpSaleOrderController, which incorrectly uses the permission namespace 'erp:sale-out' instead of the correct 'erp:sale-order' for managing sale orders. This misconfiguration allows users with shipment-level permissions to access and manipulate financially sensitive sale order operations without proper authorization. Exploitation of this vulnerability enables unauthorized creation, modification, deletion, and access to sale orders, disrupting the intended separation of duties between sales and warehouse roles.
Users should update to the version of RuoYi Vue Pro that includes the patch for this vulnerability, specifically version 2026.06 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 29, 2026CISA-ADP
Assessed Jun 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/YunaiV/ruoyi-vue-pro/issues/1161 | CISA-ADP | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/YunaiV/ruoyi-vue-pro/commit/5d1fd70dc3e61bf64e7ce3328a71cc60001175c6 | [email protected] | Source CodeVendor |
| https://github.com/YunaiV/ruoyi-vue-pro/issues/1161 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://www.vulncheck.com/advisories/ruoyi-vue-pro-incorrect-permission-namespace-in-erpsaleordercontroller | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| YunaiV ruoyi-vue-pro | <= 2026.05 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 29, 2026 | CVE Modified | CISA-ADP |
| Jun 29, 2026 | New CVE Received | [email protected] |
Volerion