PT-2026-71077 · Yuxi · Yuxi
CVE-2026-50561
·
Published
2026-08-12
·
Updated
2026-08-12
CVSS v3.1
9.4
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Yuxi versions prior to 0.6.2
Description
The authentication mechanism fails to sufficiently validate the identity token within the Authorization header, performing only a validity check. This flaw allows an administrator token generated in a different deployment instance or local testing environment to be used to access the backend management interfaces of another instance. An attacker with a valid administrator Authorization token can bypass login authentication to gain administrator privileges, enabling access to system configurations, invocation of backend management APIs, and the creation of administrator accounts, which may lead to a full system backend takeover.
Recommendations
Update to version 0.6.2.
Set the environment variable
JWT SECRET KEY to a non-default, unique, and strong value for each deployment instance.
Avoid exposing backend management interfaces directly to the public network.Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yuxi