CVE-2026-2141 | WuKongOpenSource WukongCRM up to 11.3.3 URL PermissionServiceImpl.java improper authorization
A vulnerability marked as critical has been reported in WuKongOpenSource WukongCRM up to 11.3.3. This affects an unknown part of the file gateway/src/main/java/com/kakarote/gateway/service/impl/PermissionServiceImpl.java of the component URL Handler. Performing a manipulation results in improper authorization.
This vulnerability is known as CVE-2026-2141. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.