Missing Authorization in JeecgBoot v3.9.5 Affects Department Permission Bindings
CVE-2026-108634
Key Information:
Badges
What is CVE-2026-108634?
JeecgBoot version 3.9.5 has a missing authorization flaw that permits low-privileged authenticated users to delete permissions associated with departments. This vulnerability arises from an improperly secured DELETE /sys/sysDepartPermission/deleteBatch endpoint, where users can exploit this gap by obtaining row IDs from an unsecured list endpoint. By submitting these IDs, attackers could remove specific menus and buttons assigned to departments, thereby disrupting role-based access control and potentially leading to unauthorized access within the application.
Affected Version(s)
JeecgBoot 0 <= 3.9.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
