Missing Authorization Vulnerability in JeecgBoot Affecting Low-Priority Users
CVE-2026-108677
7.1HIGH
Key Information:
Badges
👾 Exploit Exists
What is CVE-2026-108677?
JeecgBoot, up to version 3.9.5, suffers from a vulnerability that allows low-privileged authenticated users to exploit the GET /sys/api/getUserByName endpoint. This flaw enables unauthorized access to retrieve any user's stored password. Attackers can leverage the hard-coded key found in /sys/getEncryptedString to decrypt AES-CBC protected responses, gaining access to ciphertexts of administrators’ passwords, which can then be used for offline guessing attacks.
Affected Version(s)
JeecgBoot 0 <= 3.9.5
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Yaqi Chao
