CVE-2026-7710Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security flaw has been discovered in YunaiV yudao-cloud up to 3.8.0. This affects the function doFilterInternal of the file JwtAuthenticationTokenFilter.java of the component Ruoyi-Vue-Pro. Performing a manipulation of the argument mock-token results in improper authentication. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 4 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-05-04: 4Technical Details · 2026-05-04: 205-04
Signal classification1 categories
Disclosure
4100.0%
Referenced assets5 URLs
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-7710 A security flaw has been discovered in YunaiV yudao-cloud up to 3.8.0. This affects the function doFilterInternal of the file http://JwtAuthenticationTokenFilter.java of the c… https://www.cve.org/CVERecord?id=CVE-2026-7710

    Post summary

    This entry announces a vulnerability (CVE-2026-7710) in YunaiV yudao-cloud through the doFilterInternal method of JwtAuthenticationTokenFilter.java, limited to versions up to 3.8.0, and provides a link to the CVE record.

    00010325
    57.4K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-7710 📊 Severity: 7.3 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7710 #CVE-2026-7710 #CVE #High #CyberSecurity #InfoSec https://t.co/wk9Kq6s9yU

    Post summary

    This tweet announces a new CVE (CVE-2026-7710) with its severity rating and product scope, but includes no technical details, exploit code, or patch information.

    0000047
    151 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7710 A security flaw has been discovered in YunaiV yudao-cloud up to 3.8.0. This affects the function doFilterInternal of the file http://JwtAuthenticationTokenFilter.java of the c… https://www.cve.org/CVERecord?id=CVE-2026-7710 ----- Traducción: Se ha descubierto una falla… http://infoflow.cloud`

    Post summary

    A CVE-2026-7710 vulnerability affecting YunaiV yudao-cloud up to 3.8.0 was disclosed, targeting the doFilterInternal function in JwtAuthenticationTokenFilter.java.

    0000033
    75 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7710 Authentication Bypass in YunaiV yudao-cloud Up to 3.8.0 via Mock-Token Manipulation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7710

    Post summary

    A new authentication bypass vulnerability affecting YunaiV yudao-cloud up to version 3.8.0 has been disclosed, exploiting mock‑token manipulation.

    0000036
    4.0K followersView on X

Explore more