SEPTEMBER 16, 2026
Live Feed
Back to database
Case File

CVE-2026-88616

HIGH · CVSS 8.8 EPSS 0.62% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

RuoYi-Vue-Plus version 6.0.0 is vulnerable due to a flaw in the FlwTaskController.java component, which allows remote attackers to execute arbitrary code through specific service methods and POST requests. This vulnerability poses a significant risk to applications utilizing this framework, as it can lead to unauthorized access and control over the affected systems. Organizations using RuoYi-Vue-Plus should prioritize patching or mitigating this vulnerability to safeguard their environments against potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-88616
Severity
HIGH
CVSS
8.8
EPSS
0.62%
Java

Original NVD Description

An issue in RuoYi-Vue-Plus 6.0.0 allows a remote attacker to execute arbitrary code via the FlwTaskController.java component, and the FlwTaskServiceImpl.completeTask, CompleteExecuteComponent.process, Warm-Flow TaskService.skip, POST /workflow/task/completeTask components