PatchDay Alert
MAY 4, 2026

CVE

CVE-2026-7710

0 field notes · 1 digest CVSS 7.3


Daily digests

The JWT authentication filter in yudao-cloud (Ruoyi-Vue-Pro) can be bypassed by manipulating the mock-token parameter. An attacker can remotely authenticate as any user without valid credentials. A public exploit is available, and the vendor has not responded to disclosure. No patch exists.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.