CVE-2026-108112
EUVD-2026-9588509.10.2026, 16:17
ruoyi-ai 3.0.0 through 3.1.0 contains a missing authorization vulnerability that allows authenticated users to delete other users' workflows via POST /workflow/del/{uuid}. Attackers can obtain workflow UUIDs from GET /workflow/search and supply them because softDelete() skips the PrivilegeUtil.checkAndGetByUuid() ownership check, removing owners' workflows.EnginsightAwaiting analysis
This vulnerability is currently awaiting analysis.
Common Weakness Enumeration
References