What is CVE-2026-2850?
A vulnerability was found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function addCustomer/updateCustomer/deleteCustomer of the file dataset\repos\warehouse\src\main\java\com\yeqifu\bus\controller\CustomerController.java of the component Customer Endpoint. Performing a manipulation results in improper access controls. Remote exploitation of the attack is possible. The exploit has been made public and could be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.
Timeline
- 2026-02-20Published to the U.S. National Vulnerability Database (NVD)
- 2026-06-17NVD record last updated
Affected product
Yeqifu Warehouse
Remediation Steps
- Update Windows Defender/Microsoft Defender to the latest security update immediately
- Audit all user accounts for unauthorized privilege escalation in the last 30 days
- Review Microsoft Defender logs for suspicious behavior detection bypasses
- Implement application whitelisting to restrict privilege escalation vectors
- Enable enhanced logging for all privilege elevation attempts across domain controllers
References
- https://github.com/yeqifu/warehouse/issues/61
- https://github.com/yeqifu/warehouse/issues/61#issue-3846669982
- https://vuldb.com/?id.347086
- https://www.microsoft.com/en-us/security/vulnerability-management
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://nvd.nist.gov/vuln/detail/CVE-2026-2850
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 3 of April 2026 (April 20 – 26)
Browse all tracked CVEs in the defend.network CVE database →