---
id: CVE-2026-97324
title: >-
  A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to
  2026.08
summary: >-
  A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to
  2026.08. Affected is the function updateDemoOrderPaid of the file
  yudao-module-pay/src/main/java/cn/iocoder/yudao/module/pay/controller/admin/demo/PayDemoOrderCon…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-266
  - CWE-285
vendor: YunaiV
product: ruoyi-vue-pro
affected:
  - ruoyi-vue-pro 2026.08
  - ruoyi-vue-pro 2026.08
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:08:55.030'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97324'
references:
  - url: 'https://vuldb.com/cve/CVE-2026-97324'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/908275'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/409332'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/409332/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-24T19:50:30.730Z'
epss: 0.00278
epssPercentile: 0.1809
---

## Overview

A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoOrderPaid of the file yudao-module-pay/src/main/java/cn/iocoder/yudao/module/pay/controller/admin/demo/PayDemoOrderController.java of the component Demo-order Payment Callback Handler. The manipulation of the argument ID leads to improper authorization. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
