CVE-2026-2079 details an improper authorization vulnerability in the yeqifu warehouse application, specifically within the Menu Management component's addMenu/updateMenu/deleteMenu functions. This flaw, affecting versions up to commit aaf29962ba407d22d991781de28796ee7b4670e4, allows a remote attacker to manipulate menu settings. With a CVSS score of 8.8 (High), the vulnerability is easily exploitable over the network with low privileges and no user interaction, potentially leading to high impact on confidentiality, integrity, and availability. An exploit has been published, though there is no evidence of active exploitation, Metasploit modules, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2025-10-06CPE matchmatch criteria | cpe:2.3:a:yeqifu:warehouse:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.