CVE-2026-2549 MEDIUM

CVE-2026-2549: zhanghuanhao LibrarySystem 图书馆管理系统 BookController.java access control

Vendor Zhanghuanhao
Product LibrarySystem 图书馆管理系统
Weakness CWE-284
Published February 16, 2026
Last update February 23, 2026

CVSS base score

6.9/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

What the vulnerability does

Description

A vulnerability has been found in zhanghuanhao LibrarySystem 图书馆管理系统 up to 1.1.1. This impacts an unknown function of the file BookController.java. The manipulation leads to improper access controls. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Key dates

Disclosure timeline

February 16, 2026 CVE published
February 23, 2026 Record updated