CVE-2026-102293 tacomall api-admin 权限提升漏洞
影响攻击者可越权修改管理员或职位相关数据
tacomall 1.0.0 的 api-admin 后端组件中存在权限校验缺陷。OrgStaffServiceImpl.add 方法在处理 isAdmin/jobId 参数时未做正确的授权判断,导致越权操作。该漏洞可远程利用,且已有公开的利用代码。
影响范围
realjerrytang tacomall 1.0.0 的 api-admin 后端组件(ApiMaApplication.java 中的 OrgStaffServiceImpl.add 方法)。暂无其他版本受影响的信息。
漏洞详情
漏洞类型为 improper authorization(不当授权/越权)。成因是 OrgStaffServiceImpl.add 接口在新增员工时,对传入的 isAdmin、jobId 参数缺乏充分的权限与合法性校验,攻击者可自行构造请求篡改这些参数。利用方式为远程发送特制请求,从而以非授权身份设置管理员标志或指定职位。
利用条件与风险
利用前提是目标 tacomall 实例的 api-admin 接口可被远程访问,且攻击者能构造相应请求;由于利用代码已公开,实战中被扫描和利用的风险较高。
修复建议
建议关注厂商 realjerrytang 是否发布 tacomall 的修复版本并尽快升级;临时缓解措施包括限制 api-admin 接口的访问来源、增加鉴权与参数校验,暂无公开的官方补丁信息。
A vulnerability was identified in realjerrytang tacomall 1.0.0. Impacted is the function OrgStaffServiceImpl.add of the file ApiMaApplication.java of the component api-admin Backend. The manipulation of the argument isAdmin/jobId leads to improper authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.