CVE-2026-58448 Details
Description
yudao-cloud before 2026.06 contains a broken access control vulnerability in the BPM module that allows any authenticated user to access arbitrary process instance records by supplying a caller-controlled process-instance identifier to an unprotected endpoint lacking the @PreAuthorize annotation. Attackers can query any process-instance identifier through the unguarded GET endpoint to read sensitive workflow data including submitted form variables, approver identities, approval and rejection comments, and process BPMN XML without ownership or tenant party verification.
A broken access control vulnerability has been identified in the Yudao Cloud BPM module, affecting versions prior to 2026.06. This vulnerability allows any authenticated user to access arbitrary process instance records by supplying a caller-controlled process-instance identifier to an unprotected endpoint that lacks the necessary authorization annotation. Exploitation of this vulnerability enables unauthorized users to read sensitive workflow data, including submitted form variables, identities of approvers, approval and rejection comments, and the process BPMN XML, without any verification of ownership or tenant party.
Users are advised to update to Yudao Cloud version 2026.06 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 30, 2026CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/YunaiV/yudao-cloud/issues/315 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/YunaiV/yudao-cloud/releases#release-v2026.06(jdk8/11) | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/yudao-cloud-bpm-module-broken-access-control-via-process-instance-api | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| YunaiV yudao-cloud | < 2026.06 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | New CVE Received | [email protected] |
Volerion