


Perceptive Security
SOC/SIEM Consultancy

Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside of their scope.
Published:
22 januari 2026 om 23:00:00
Alert date:
23 januari 2026 om 21:02:30
Source:
nvd.nist.gov
Enterprise Applications, Identity & Access
CVE-2025-70985 is a critical access control vulnerability in RuoYi v4.8.2, a Java-based enterprise management framework. The vulnerability exists in the update function and allows unauthorized attackers to arbitrarily modify data outside of their permitted scope. This represents a significant security flaw that could allow privilege escalation and unauthorized data manipulation. The vulnerability affects the access control mechanisms that should restrict users to only modify data within their authorized boundaries. Given the widespread use of RuoYi in enterprise environments, this vulnerability poses a high risk to organizational data integrity and security.
Technical details
Mitigation steps:
Affected products:
RuoYi
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-70985
https://gist.github.com/old6ma/1a2dada02656ba9a4730c85f6c765f4f
https://gitee.com/y_project/RuoYi
https://gitee.com/y_project/RuoYi/issues/IDIDK2
https://github.com/yangzongzhuan/RuoYi
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
