CVE-2025-55469
26.11.2025, 18:15
Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and access the Administrator backend.Enginsight
| Vendor | Product | Version |
|---|---|---|
| youlai | youlai-boot | 2.21.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-863 - Incorrect AuthorizationThe software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
- CWE-284 - Improper Access ControlThe software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.