CVE-2025-66735

high

Description

youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The getRoleForm function in SysRoleController.java does not perform permission checks, which may allow non-root users to directly access root roles.

References

https://gitee.com/youlaiorg/youlai-boot/issues/ICH8FR

https://gitee.com/youlaiorg/youlai-boot/commit/9197065102f92264ded814a9d3e9f2a4ff0da121

https://gist.github.com/old6ma/dc9e6e4a693d12c1a35fd4e1d21d4743

Details

Source: Mitre, NVD

Published: 2025-12-22

Updated: 2026-01-06

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: High

EPSS

EPSS: 0.0003