---
id: CVE-2026-92461
title: >-
  yshop-crm through 2.1.3 contains a missing authorization vulnerability in the
  GET /admin-api/crm/flow/flow-users endpoint that allows any logged-in
  back-office user to access approval workflow data
summary: >-
  yshop-crm through 2.1.3 contains a missing authorization vulnerability in the
  GET /admin-api/crm/flow/flow-users endpoint that allows any logged-in
  back-office user to access approval workflow data. Attackers can retrieve
  approval chain …
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-862
vendor: guchengwuyue
product: yshop-crm
affected:
  - yshop-crm <= 2.1.3
published: '2026-09-16'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T11:10:00.187'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92461'
references:
  - url: >-
      https://github.com/LinYuanyi1/cve-request-poc/blob/master/yshop-crm/C08_crm_flow_users.py
    label: disclosure@vulncheck.com
  - url: 'https://github.com/guchengwuyue/yshop-crm'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/guchengwuyue/yshop-crm/blob/5f5810a0e1e4ab0828523ec299bf973c2f9065d7/yshop-crm/pom.xml#L30
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/guchengwuyue/yshop-crm/blob/5f5810a0e1e4ab0828523ec299bf973c2f9065d7/yshop-crm/yshop-module-crm/yshop-module-crm-biz/src/main/java/co/yixiang/yshop/module/crm/controller/admin/crmflow/CrmFlowController.java#L94
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/guchengwuyue/yshop-crm/blob/5f5810a0e1e4ab0828523ec299bf973c2f9065d7/yshop-crm/yshop-module-crm/yshop-module-crm-biz/src/main/java/co/yixiang/yshop/module/crm/service/crmflow/CrmFlowServiceImpl.java#L132
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/yshop-crm-through-2.1.3-missing-authorization-via-crm-approval-chain-endpoint
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00378
epssPercentile: 0.29074
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-16T13:34:44.317642Z'
ingestedAt: '2026-09-16T11:54:38.962Z'
---

## Overview

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the GET /admin-api/crm/flow/flow-users endpoint that allows any logged-in back-office user to access approval workflow data. Attackers can retrieve approval chain topology, step ordering, approver identifiers, and personal information including login names, nicknames, departments, email addresses, mobile numbers and last login IP addresses.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
