
CVE-2026-58448 yudao-cloud before 2026.06 contains a broken access control vulnerability in the BPM module that allows any authenticated user to access arbitrary process instance re… https://www.cve.org/CVERecord?id=CVE-2026-58448
Post summary
CVE-2026-58448 details a broken access control flaw in yudao‑cloud’s BPM module that lets authenticated users access any process instance, with no reported exploitation or mitigation information available.
