CVE-2026-97324 Details
Description
A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoOrderPaid of the file yudao-module-pay/src/main/java/cn/iocoder/yudao/module/pay/controller/admin/demo/PayDemoOrderController.java of the component Demo-order Payment Callback Handler. The manipulation of the argument ID leads to improper authorization. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
An improper authorization vulnerability has been identified in YunaiV/zhijiantianya ruoyi-vue-pro versions prior to 2026.08. The issue arises in the Demo-order Payment Callback Handler, specifically within the updateDemoOrderPaid function of the PayDemoOrderController.java file. The vulnerability allows for remote exploitation by manipulating the argument ID, leading to unauthorized actions.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vuldb.com/cve/CVE-2026-97324 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/908275 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/409332 | [email protected] | BundlePermission Required |
| https://vuldb.com/vuln/409332/cti | [email protected] | Permission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-285 | Improper Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| YunaiV/zhijiantianya ruoyi-vue-pro | <= 2026.08 |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 24, 2026 | New CVE Received | [email protected] |
Volerion