top of page
perceptive_background_267k.jpg

Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside of their scope.

Published:

22 januari 2026 om 23:00:00

Alert date:

23 januari 2026 om 21:02:30

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Identity & Access

CVE-2025-70985 is a critical access control vulnerability in RuoYi v4.8.2, a Java-based enterprise management framework. The vulnerability exists in the update function and allows unauthorized attackers to arbitrarily modify data outside of their permitted scope. This represents a significant security flaw that could allow privilege escalation and unauthorized data manipulation. The vulnerability affects the access control mechanisms that should restrict users to only modify data within their authorized boundaries. Given the widespread use of RuoYi in enterprise environments, this vulnerability poses a high risk to organizational data integrity and security.

Technical details

Mitigation steps:

Affected products:

RuoYi

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page