CVE-2026-77036

Summary

A vulnerability was found in elunez eladmin up to 2.7. The impacted element is the function EmailController/AliPayController/GeneratorController/GenConfigController. The manipulation results in improper authorization. The attack can be launched remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

Affected Software

VendorProductVersion RangeStatus
elunezeladmin2.0affected
elunezeladmin2.1affected
elunezeladmin2.2affected
elunezeladmin2.3affected
elunezeladmin2.4affected
elunezeladmin2.5affected
elunezeladmin2.6affected
elunezeladmin2.7affected

Weaknesses

  • CWE-285: Improper Authorization
  • CWE-266: Incorrect Privilege Assignment

References