Executive brief
yudao-cloud is an open-source development platform used for building enterprise management systems. A security flaw in its Business Process Management (BPM) module allows any logged-in user to view sensitive workflow information that they are not authorized to see. This includes private form data, the identities of approvers, internal comments, and the organizational logic of business processes, potentially leading to the exposure of confidential business operations and personal employee information.
Technical details
A broken access control vulnerability exists in the BPM module of yudao-cloud due to a missing authorization check. Specifically, the 'get-bpmn-model-view' endpoint in BpmProcessInstanceController.java lacks the @PreAuthorize annotation used by other endpoints in the same controller. An authenticated attacker can exploit this by sending a GET request to '/bpm/process-instance/get-bpmn-model-view' with a specific process-instance ID. This allows the retrieval of sensitive data including form variables, approver identities, rejection comments, and BPMN XML definitions without ownership or tenant verification. The vulnerability is addressed in version 2026.06.
Affected products
- YunaiV yudao-cloud < 2026.06
Timeline
- 2026-06-30: disclosed: Vulnerability reported via GitHub Issue #315
- 2026-06-30: patched: Fixed in version 2026.06 release
- 2026-06-30: advisory