Missing Authorization Vulnerability in JeecgBoot by Jeecg
CVE-2026-108637
Key Information:
Badges
What is CVE-2026-108637?
JeecgBoot version 3.9.5 is affected by a vulnerability that allows low-privileged authenticated users to delete user group members without proper authorization. By exploiting the DELETE /sys/user/deleteUserGroupBatch endpoint, attackers can bypass permissions and remove users from groups managed by administrators. This unauthorized access leads to potential mishandling of user permissions within the system, compromising the integrity of user group management.
Affected Version(s)
JeecgBoot 0 <= 3.9.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
