Missing Authorization Vulnerability in JeecgBoot by Jeecg
CVE-2026-108631
Key Information:
Badges
What is CVE-2026-108631?
JeecgBoot version 3.9.5 has a critical security flaw in its SysDepartPermissionController delete handler. This vulnerability allows low-privileged authenticated users to delete department permission bindings. Attackers can exploit this by obtaining row IDs from an unguarded list endpoint, enabling them to craft DELETE requests using the ID parameter, effectively removing essential menus or buttons that departments can assign to their roles. This flaw presents significant risks to the integrity of permission management within the system.
Affected Version(s)
JeecgBoot 0 <= 3.9.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
