CVE-2025-70985
Severity CVSS v4.0:
Pending analysis
Type:
CWE-284
Improper Access Control
Publication date:
23/01/2026
Last modified:
23/01/2026
Description
Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside of their scope.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL



