PT-2026-71077 · Yuxi · Yuxi

CVE-2026-50561

·

Published

2026-08-12

·

Updated

2026-08-12

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Yuxi versions prior to 0.6.2
Description The authentication mechanism fails to sufficiently validate the identity token within the Authorization header, performing only a validity check. This flaw allows an administrator token generated in a different deployment instance or local testing environment to be used to access the backend management interfaces of another instance. An attacker with a valid administrator Authorization token can bypass login authentication to gain administrator privileges, enabling access to system configurations, invocation of backend management APIs, and the creation of administrator accounts, which may lead to a full system backend takeover.
Recommendations Update to version 0.6.2. Set the environment variable JWT SECRET KEY to a non-default, unique, and strong value for each deployment instance. Avoid exposing backend management interfaces directly to the public network.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50561
GHSA-6959-99PQ-C56X

Affected Products

Yuxi