Metrics
Affected Vendors & Products
Tue, 10 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:yeqifu:warehouse:*:*:*:*:*:*:*:* |
Mon, 09 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yeqifu
Yeqifu warehouse |
|
| Vendors & Products |
Yeqifu
Yeqifu warehouse |
Sat, 07 Feb 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. The impacted element is the function addNotice/updateNotice/deleteNotice/batchDeleteNotice of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\NoticeController.java of the component Notice Management. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | yeqifu warehouse Notice Management NoticeController.java batchDeleteNotice improper authorization | |
| Weaknesses | CWE-266 CWE-285 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-02-07T17:32:06.820Z
Updated: 2026-02-23T09:33:32.862Z
Reserved: 2026-02-06T14:16:00.975Z
Link: CVE-2026-2106
Updated: 2026-02-10T15:59:55.464Z
Status : Analyzed
Published: 2026-02-07T18:15:47.310
Modified: 2026-02-10T15:13:15.323
Link: CVE-2026-2106
No data.