What is CVE-2026-2852?
A vulnerability was identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects the function addSales/updateSales/deleteSales of the file dataset\repos\warehouse\src\main\java\com\yeqifu\bus\controller\SalesController.java of the component Sales Endpoint. The manipulation leads to improper access controls. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.
Timeline
- 2026-02-20Published to the U.S. National Vulnerability Database (NVD)
- 2026-06-17NVD record last updated
Affected product
Yeqifu Warehouse
Remediation Steps
- Update protobuf.js library to the latest patched version across all JavaScript applications
- Review dependency manifests to identify all affected package consumers
- Implement Content Security Policy (CSP) to restrict malicious script execution
- Audit recent network traffic for suspicious code execution patterns
- Run security scanning tools to detect protobuf deserialization attempts in logs
References
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 3 of April 2026 (April 20 – 26)
Browse all tracked CVEs in the defend.network CVE database →