Missing Authorization Vulnerability in JeecgBoot OpenApiController
CVE-2026-108653
5.3MEDIUM
What is CVE-2026-108653?
JeecgBoot versions up to 3.9.5 contain a vulnerability in the OpenApiController's queryPageList handler, where a lack of proper authorization mechanisms allows any authenticated user to access and list OpenAPI registry definitions. This issue can be exploited by low-privileged attackers through a simple GET request to /openapi/list, enabling them to retrieve sensitive information such as virtual paths, internal origin URLs, IP whitelists, and header and parameter templates that are intended only for administrative use. As a result, this vulnerability poses a significant risk to the confidentiality of sensitive application data.
Affected Version(s)
JeecgBoot 0 <= 3.9.5
