A vulnerability has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this issue is the function deleteCache/removeAllCache/syncCache of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\CacheController.java of the component Cache Sync Handler. Such manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.
References
| Link | Resource |
|---|---|
| https://github.com/yeqifu/warehouse/ | Product |
| https://github.com/yeqifu/warehouse/issues/60 | Exploit Issue Tracking |
| https://github.com/yeqifu/warehouse/issues/60#issue-3846666902 | Exploit Issue Tracking |
| https://vuldb.com/?ctiid.347085 | Permissions Required VDB Entry |
| https://vuldb.com/?id.347085 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.754428 | Third Party Advisory VDB Entry |
Configurations
History
26 Feb 2026, 02:41
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/yeqifu/warehouse/ - Product | |
| References | () https://github.com/yeqifu/warehouse/issues/60 - Exploit, Issue Tracking | |
| References | () https://github.com/yeqifu/warehouse/issues/60#issue-3846666902 - Exploit, Issue Tracking | |
| References | () https://vuldb.com/?ctiid.347085 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.347085 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.754428 - Third Party Advisory, VDB Entry | |
| Summary |
|
|
| CPE | cpe:2.3:a:yeqifu:warehouse:*:*:*:*:*:*:*:* | |
| First Time |
Yeqifu warehouse
Yeqifu |
20 Feb 2026, 17:25
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-20 17:25
Updated : 2026-02-26 02:41
NVD link : CVE-2026-2849
Mitre link : CVE-2026-2849
CVE.ORG link : CVE-2026-2849
JSON object : View
Products Affected
yeqifu
- warehouse
