MEDIUM
RuoYi-Cloud-Plus
CVE published 2026-09-09
CVE-2026-71807
CVE-2026-71807 debrief based on the supplied source corpus. The vulnerability in RuoYi-Cloud-Plus <= 2.6.2, specifically in the ruoyi-workflow module, allows authenticated low-privileged remote attackers to read sensitive workflow task details and trigger unauthorized workflow executions due to lacking permission annotations in FlwTaskController and insufficient verification of user roles. This issue can [truncated]