In RuoYi-Cloud-Plus <= 2.6.2 in the ruoyi-workflow module, multiple core task APIs in FlwTaskController lack permission annotations, and the Service layer does not verify whether the current user is the task handler/related user. Authenticated low-privileged remote attackers can read sensitive workflow task details (/task/getTask/{taskId}) and trigger unauthorized workflow executions (/task/startWorkFlow).
CVE-2026-71807
NONE
EPSS 0.19%
Updated Sep 10, 2026
In
CVE Details
CVE ID
CVE-2026-71807
Published Date
Sep 10, 2026
Vendor
In
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.19%
Likelihood of exploitation in next 30 days
Percentile:
9.2th percentile (higher than 9.2% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory