A vulnerability was identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects the function addSales/updateSales/deleteSales of the file dataset\repos\warehouse\src\main\java\com\yeqifu\bus\controller\SalesController.java of the component Sales Endpoint. The manipulation leads to improper access controls. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.
References
| Link | Resource |
|---|---|
| https://github.com/yeqifu/warehouse/ | Product |
| https://github.com/yeqifu/warehouse/issues/63 | Exploit Issue Tracking |
| https://github.com/yeqifu/warehouse/issues/63#issue-3846671301 | Issue Tracking |
| https://vuldb.com/?ctiid.347088 | Permissions Required VDB Entry |
| https://vuldb.com/?id.347088 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.754431 | Third Party Advisory VDB Entry |
Configurations
History
26 Feb 2026, 20:43
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/yeqifu/warehouse/ - Product | |
| References | () https://github.com/yeqifu/warehouse/issues/63 - Exploit, Issue Tracking | |
| References | () https://github.com/yeqifu/warehouse/issues/63#issue-3846671301 - Issue Tracking | |
| References | () https://vuldb.com/?ctiid.347088 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.347088 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.754431 - Third Party Advisory, VDB Entry | |
| Summary |
|
|
| CPE | cpe:2.3:a:yeqifu:warehouse:*:*:*:*:*:*:*:* | |
| First Time |
Yeqifu warehouse
Yeqifu |
20 Feb 2026, 19:23
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-20 19:23
Updated : 2026-02-26 20:43
NVD link : CVE-2026-2852
Mitre link : CVE-2026-2852
CVE.ORG link : CVE-2026-2852
JSON object : View
Products Affected
yeqifu
- warehouse
