Description
In RuoYi-Cloud-Plus <= 2.6.2 in the ruoyi-workflow module, multiple core task APIs in FlwTaskController lack permission annotations, and the Service layer does not verify whether the current user is the task handler/related user. Authenticated low-privileged remote attackers can read sensitive workflow task details (/task/getTask/{taskId}) and trigger unauthorized workflow executions (/task/startWorkFlow).
Published: 2026-09-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized workflow execution and data disclosure
Action: Patch
AI Analysis

Impact

The vulnerability originates from missing permission annotations on several core task APIs in the FlwTaskController and from a Service layer that does not verify whether the current user is the task handler or a related user, allowing authenticated low‑privileged remote attackers to read sensitive workflow task details through /task/getTask/{taskId} and to trigger unauthorized workflow executions via /task/startWorkFlow.

Affected Systems

Versions of RuoYi-Cloud-Plus up to and including 2.6.2 within the ruoyi-workflow module are vulnerable, specifically the FlwTaskController and its associated request paths.

Risk and Exploitability

The attack vector requires an authenticated account with low privileges but does not require escalation, as inferred from the description. Once authenticated, the attacker can read internal workflow metadata and initiate workflow instances that could alter business processes or expose confidential data. The CVSS score is 4.3, the EPSS score is less than 1%, and the vulnerability is not listed in CISA's KEV catalog. Based on the available information, the risk could be moderate due to the potential for data leakage and unauthorized process execution without privilege escalation.

Generated by OpenCVE AI on September 21, 2026 at 05:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade RuoYi-Cloud-Plus to a version newer than 2.6.2 or apply any official patches that add missing permission checks to the FlwTaskController
  • Add explicit permission annotations or other authorization controls to all task‑related endpoints so that only users with the correct role or task ownership can access them
  • Modify the service layer to enforce ownership checks before performing operations on workflow tasks
  • If upgrading is not immediately possible, restrict low‑privileged accounts from accessing the affected endpoints via network firewalls or application‑level access controls

Generated by OpenCVE AI on September 21, 2026 at 05:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 21 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Access to Workflow Tasks in RuoYi-Cloud-Plus

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Ruoyi
Ruoyi ruoyi-cloud-plus
Vendors & Products Ruoyi
Ruoyi ruoyi-cloud-plus

Thu, 10 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Access to Workflow Tasks in RuoYi-Cloud-Plus
Weaknesses CWE-284

Wed, 09 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description In RuoYi-Cloud-Plus <= 2.6.2 in the ruoyi-workflow module, multiple core task APIs in FlwTaskController lack permission annotations, and the Service layer does not verify whether the current user is the task handler/related user. Authenticated low-privileged remote attackers can read sensitive workflow task details (/task/getTask/{taskId}) and trigger unauthorized workflow executions (/task/startWorkFlow).
References

Subscriptions

Ruoyi Ruoyi-cloud-plus
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T16:57:49.795Z

Reserved: 2026-08-07T00:00:00.000Z

Link: CVE-2026-71807

cve-icon Vulnrichment

Updated: 2026-09-14T16:57:41.324Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T22:18:19.173

Modified: 2026-09-14T17:17:50.237

Link: CVE-2026-71807

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:15:09Z

Weaknesses