SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-16450

MEDIUM · CVSS 4.3 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

The vulnerability in zsadmin2025 ZS-Admin allows for an authorization bypass through manipulation of the X-Tenant-Id argument in the MyBatis-Plus Tenant Plugin's getTenantId function. This issue can be exploited remotely, and public exploit code is available, making it critical for organizations using this software to prioritize remediation. Given the lack of disclosed version information and the ongoing rolling release system, users should assess their deployments urgently to mitigate potential risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-16450
Severity
MEDIUM
CVSS
4.3
EPSS
0.27%

Original NVD Description

A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the function getTenantId of the file /api/system/sys/dept/page of the component MyBatis-Plus Tenant Plugin. Such manipulation of the argument X-Tenant-Id leads to authorization bypass. The attack may be performed from remote. The exploit is publicly available and might be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.