Missing Authorization Vulnerability in JeecgBoot SystemApiController
CVE-2026-108679
Key Information:
Badges
What is CVE-2026-108679?
JeecgBoot versions up to 3.9.5 are affected by a missing authorization vulnerability in the sendBusAnnouncement handler located in SystemApiController. This flaw allows authenticated users to send announcements without the appropriate permissions. Attackers with low privileges can exploit this vulnerability by sending crafted POST requests to the /sys/api/sendBusAnnouncement endpoint. By forging the sender, recipients, title, and content fields, they can deliver spoofed messages that appear to come from administrators or the system itself, which poses significant risks for phishing attacks and unauthorized information dissemination.
Affected Version(s)
JeecgBoot 0 <= 3.9.5
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
