CVE-2026-71807
Deferred Deferred - Pending Action

Permission Bypass in RuoYi-Cloud-Plus Workflow Module

Vulnerability report for CVE-2026-71807, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: MITRE

Description

In RuoYi-Cloud-Plus <= 2.6.2 in the ruoyi-workflow module, multiple core task APIs in FlwTaskController lack permission annotations, and the Service layer does not verify whether the current user is the task handler/related user. Authenticated low-privileged remote attackers can read sensitive workflow task details (/task/getTask/{taskId}) and trigger unauthorized workflow executions (/task/startWorkFlow).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ruoyi ruoyi-cloud-plus 2.6.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in RuoYi-Cloud-Plus versions 2.6.2 and earlier. It involves missing permission checks in the workflow module's task APIs. Specifically, the FlwTaskController endpoints for retrieving task details and starting workflows do not enforce proper authorization. This allows authenticated low-privileged users to access sensitive task information or trigger unauthorized workflow executions.

Detection Guidance

To detect this vulnerability, check if your RuoYi-Cloud-Plus version is 2.6.2 or lower. Inspect the ruoyi-workflow module for missing permission annotations in FlwTaskController APIs and verify if the Service layer lacks user verification for task handlers. Look for unauthorized access attempts to /task/getTask/{taskId} or /task/startWorkFlow endpoints.

Impact Analysis

An attacker could exploit this to read confidential workflow task data or initiate workflows without proper authorization. This could lead to unauthorized actions, data leaks, or workflow disruptions in systems using RuoYi-Cloud-Plus. The impact depends on the sensitivity of the workflow tasks and the system's configuration.

Compliance Impact

This vulnerability could violate compliance requirements by exposing sensitive data or allowing unauthorized workflow actions. GDPR may be impacted if personal data is exposed, while HIPAA could be affected if protected health information is compromised. Organizations must assess their specific workflow data to determine compliance risks.

Mitigation Strategies

Upgrade RuoYi-Cloud-Plus to a version higher than 2.6.2 where permission annotations are added and service layer validates task handlers. If immediate upgrade is not possible, restrict access to the /task/getTask/{taskId} and /task/startWorkFlow endpoints via network controls or WAF rules.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71807. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart