CVE-2025-66735

youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The getRoleForm function in SysRoleController.java does not perform permission checks, which may allow non-root users to directly access root roles.

high 7.5 CVSS 3.1
Published: Dec 22, 2025
Modified: Jan 6, 2026
Vendor: Youlai
Product: Youlai-Boot
Versions: 2.21.1

Description

youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The getRoleForm function in SysRoleController.java does not perform permission checks, which may allow non-root users to directly access root roles.

References

Related CVEs