Ad

CVE-2026-2141

MEDIUM CVSS 4.0: 5.3 EPSS 0.01%
Updated Feb 08, 2026
Java
Parameter Value
CVSS 5.3 (MEDIUM)
Type CWE-266 (Incorrect Privilege Assignment (Неправильное назначение привилегий)), CWE-285 (Improper Authorization (Некорректная авторизация))
Vendor Java
Public PoC No

A security flaw has been discovered in WuKongOpenSource WukongCRM up to 11.3.3. This affects an unknown part of the file gateway/src/main/java/com/kakarote/gateway/service/impl/PermissionServiceImpl.java of the component URL Handler. Performing a manipulation results in improper authorization.

Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Attack Parameters

Attack Vector
Network
Атака возможна удалённо
Attack Complexity
Low
Легко эксплуатировать
Attack Requirements
None
Нет дополнительных условий
Privileges Required
Low
Нужны базовые права
User Interaction
None
Не нужно действие пользователя

Impact Assessment

Confidentiality
Low
Частичная утечка данных
Integrity
Low
Частичная модификация данных
Availability
Low
Частичное нарушение работы

CVSS Vector v4.0