CVE-2026-57949
Yunai ruoyi-vue-pro
ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module's GET /admin-api/crm/follow-up-record/get endpoint that allows authenticated users to read any follow-up record by iterating sequential numeric IDs. Attackers can exploit this by sending requests with arbitrary ID parameters to access other users' follow-up notes, file attachments, scheduling information, and business entity references without proper authorization checks.
- CVSS
- 7.1
- EPSS
- 0.23% 14.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.30