Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
6.9
Rongzhitong Visual Integrated Command and Dispatch Platform: Unapproved Access to User Data
CVE-2026-2669
Summary
The Rongzhitong Visual Integrated Command and Dispatch Platform has a security weakness that allows unauthorized access to user information. This means that a hacker could potentially access sensitive data about users, and there's a publicly available exploit that could be used to do this. We recommend that Rongzhitong takes immediate action to address this issue to protect their users.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| rongzhitong | visual_integrated_command_and_dispatch_platform | <= 2026-02-06 | – |
Original title
A vulnerability was determined in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This impacts an unknown function of the file /dm/dispatch/user/delete of the component ...
Original description
A vulnerability was determined in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This impacts an unknown function of the file /dm/dispatch/user/delete of the component User Handler. This manipulation of the argument ID causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
nvd CVSS2.0
6.4
nvd CVSS3.1
6.5
nvd CVSS4.0
6.9
Vulnerability type
CWE-266
Incorrect Privilege Assignment
CWE-284
Improper Access Control
- https://github.com/21151213732/CVE/blob/main/VICDP-Unauthorized%20Access3.md Exploit Third Party Advisory
- https://vuldb.com/?ctiid.346466 Permissions Required VDB Entry
- https://vuldb.com/?id.346466 Third Party Advisory VDB Entry
- https://vuldb.com/?submit.753294 Third Party Advisory VDB Entry
Published: 18 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026