Missing Authorization in JeecgBoot SysAnnouncementController Affects User-Accessed Attachments
CVE-2026-108676
Key Information:
Badges
What is CVE-2026-108676?
JeecgBoot version 3.9.5 features a vulnerability in the SysAnnouncementController that permits unauthorized file download access. Specifically, low-privileged authenticated users can manipulate the downLoadFiles handler to obtain ZIP files containing attachments from announcements. This exploitation occurs due to the absence of proper authorization checks, allowing the retrieval of sensitive information from announcements intended for different user groups or unreleased content.
Affected Version(s)
JeecgBoot 0 <= 3.9.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
