Authorization Bypass in JeecgBoot allows Unauthorized Access to User Video Records
CVE-2026-108672
Key Information:
Badges
What is CVE-2026-108672?
JeecgBoot versions up to 3.9.5 have a vulnerability in the getVideoRecords handler within the VideoGenerationController. This issue allows authenticated users to bypass authorization checks, enabling them to access the video generation history of other users. By manipulating the userId parameter, low-privileged attackers can retrieve sensitive information including AI video generation prompts, task IDs, video URLs, and cover images, potentially compromising user privacy and security.
Affected Version(s)
JeecgBoot 0 <= 3.9.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
