๐Ÿ” CVE Alert

CVE-2026-92462

MEDIUM 6.5

yshop-crm through 2.1.3 Missing Authorization via CrmFlowController deleteFlowStep

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

yshop-crm through 2.1.3 fails to enforce authorization checks on the CrmFlowController deleteFlowStep endpoint, allowing any authenticated back-office user to delete arbitrary approval workflow steps. Attackers can invoke the DELETE /admin-api/crm/flow/delete-step endpoint without required permissions to remove approval steps that control contract, receivable, and invoice finalization processes.

CWE CWE-862
Vendor guchengwuyue
Product yshop-crm
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for guchengwuyue yshop-crm

Be the first to know when new medium vulnerabilities affecting guchengwuyue yshop-crm are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None

Affected Versions

guchengwuyue / yshop-crm
0 โ‰ค 2.1.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/LinYuanyi1/cve-request-poc/blob/master/yshop-crm/C09_crm_flow_delete_step.py github.com: https://github.com/guchengwuyue/yshop-crm/blob/5f5810a0e1e4ab0828523ec299bf973c2f9065d7/yshop-crm/yshop-module-crm/yshop-module-crm-biz/src/main/java/co/yixiang/yshop/module/crm/controller/admin/crmflow/CrmFlowController.java#L102 github.com: https://github.com/guchengwuyue/yshop-crm/blob/5f5810a0e1e4ab0828523ec299bf973c2f9065d7/yshop-crm/yshop-module-crm/yshop-module-crm-biz/src/main/java/co/yixiang/yshop/module/crm/service/crmflow/CrmFlowServiceImpl.java#L230 github.com: https://github.com/guchengwuyue/yshop-crm/blob/5f5810a0e1e4ab0828523ec299bf973c2f9065d7/yshop-crm/pom.xml#L30 github.com: https://github.com/guchengwuyue/yshop-crm vulncheck.com: https://www.vulncheck.com/advisories/yshop-crm-through-2.1.3-missing-authorization-via-crmflowcontroller-deleteflowstep

Credits

Mingsheng Lin (lincoke)