Yeqifu Warehouse Improper Authorization Vulnerability in User Management Endpoint

Vulnerability

A vulnerability exists in Yeqifu Warehouse versions up to commit aaf29962ba407d22d991781de28796ee7b4670e4, specifically within the User Management Endpoint. The issue arises in the UserController.java file, particularly in the addUser, updateUser, and deleteUser functions. This vulnerability allows improper authorization, enabling any logged-in user to create, modify, or delete user accounts. Such actions could lead to account takeover, the creation of backdoor accounts, and denial-of-service by removing legitimate users.

Impact

Exploitation of this vulnerability allows for improper authorization, enabling unauthorized users to perform user account management actions such as creating, updating, or deleting accounts. This could result in account takeover, unauthorized access to user privileges, and disruption of service by removing legitimate users.

Reproduction

To reproduce this vulnerability, log in as a user with low privileges. Once logged in, send a request to the deleteUser endpoint, targeting an admin user. The request will be processed successfully, and the admin user will be deleted.

Added: Feb 7, 2026, 7:18 AM
Updated: Feb 7, 2026, 7:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.6
exploitability
6.6
remediation
0.0
relevance
2.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.