CVE-2026-97324

HIGH Status: Deferred

CVSS Scores

CVSS v3.x Base Score
7.3
HIGH
CVSS v2 Base Score
7.5
HIGH

Description

A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoOrderPaid of the file yudao-module-pay/src/main/java/cn/iocoder/yudao/module/pay/controller/admin/demo/PayDemoOrderController.java of the component Demo-order Payment Callback Handler. The manipulation of the argument ID leads to improper authorization. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Published
September 24, 2026 8:17 PM
Last Modified
September 24, 2026 9:08 PM
Source
[email protected]

Weaknesses (CWE)

CWE-266 CWE-285

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.