Dromara · Ruoyi-Vue-Plus · CVE-2026-77795
**Name of the Vulnerable Software and Affected Versions**
Dromara RuoYi-Vue-Plus versions prior to 5.6.3
**Description**
Improper authorization exists within the Workflow Endpoint component. This issue allows a remote attacker to perform unauthorized actions through the following functions: `FlwInstanceController()`, `FlwDefinitionController()`, `FlwCategoryController()`, `FlwSpelController()`, and `TestLeaveController()`.
**Recommendations**
Update Dromara RuoYi-Vue-Plus to version 5.6.3 or later.
As a temporary mitigation, restrict access to the `FlwInstanceController()`, `FlwDefinitionController()`, `FlwCategoryController()`, `FlwSpelController()`, and `TestLeaveController()` functions.