Missing Authorization Vulnerability in JeecgBoot by Jeecg
CVE-2026-108651
Key Information:
Badges
What is CVE-2026-108651?
JeecgBoot versions up to 3.9.5 suffer from a missing authorization vulnerability in the getRolesByUserId handler within the SystemApiController. This flaw allows authenticated users with low privileges to exploit the endpoint /sys/api/getRolesByUserId by supplying arbitrary userId values. As a result, these users can enumerate role assignments, potentially identifying and compromising administrator accounts. This vulnerability highlights the need for robust access controls to prevent unauthorized information disclosure.
Affected Version(s)
JeecgBoot 0 <= 3.9.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
