Vulnerability Title: warehouse latest(git commit aaf29962ba407d22d991781de28796ee7b4670e4) Improper Access Controls Description: The Customer, provider, and goods CRUD endpoints do not enforce permissions (add/delete/update). Any logged-in user can alter or delete core business data, resulting in integrity loss, fraudulent records, and potential operational disruption. Proper role-based access control should be enforced for each action, with validation of ownership where applicable. Source: GitHub issue User: AliceS614 (UID 94277) Submission Date: 02/09/2026 05:55 AM Moderation Date: 02/20/2026 10:01 AM Status: Accepted VuDB Entry: 347086 - yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4 Customer Endpoint CustomerController.java addCustomer/updateCustomer/deleteCustomer access control Points: 18