Elunez · Eladmin · CVE-2026-77036
**Name of the Vulnerable Software and Affected Versions**
elunez eladmin versions prior to 2.8
**Description**
Improper authorization occurs within the `EmailController()`, `AliPayController()`, `GeneratorController()`, and `GenConfigController()` functions. This flaw allows a remote attacker to bypass authorization mechanisms.
**Recommendations**
As a temporary workaround, restrict access to the `EmailController()`, `AliPayController()`, `GeneratorController()`, and `GenConfigController()` functions until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.