Missing Authorization Vulnerability in JeecgBoot by Jeecg
CVE-2026-108633
Key Information:
Badges
What is CVE-2026-108633?
JeecgBoot versions up to 3.9.5 are susceptible to a missing authorization vulnerability that permits low-privileged authenticated users to create and manipulate department permission bindings. This vulnerability arises when users submit a POST request to /sys/sysDepartPermission/add, allowing them to pass arbitrary department IDs, permission IDs, and data rule IDs. As a result, attackers can delegate menu, button, and data rule grants to any department role, potentially leading to unauthorized access and privilege escalation. Organizations utilizing JeecgBoot should assess their systems and implement mitigations to avoid exploitation.
Affected Version(s)
JeecgBoot 0 <= 3.9.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
