Missing Authorization Vulnerability in JeecgBoot SystemApiController
CVE-2026-108679

5.3MEDIUM

Key Information:

Vendor

Jeecgboot

Status
Vendor
CVE Published:
10 October 2026

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2026-108679?

JeecgBoot versions up to 3.9.5 are affected by a missing authorization vulnerability in the sendBusAnnouncement handler located in SystemApiController. This flaw allows authenticated users to send announcements without the appropriate permissions. Attackers with low privileges can exploit this vulnerability by sending crafted POST requests to the /sys/api/sendBusAnnouncement endpoint. By forging the sender, recipients, title, and content fields, they can deliver spoofed messages that appear to come from administrators or the system itself, which poses significant risks for phishing attacks and unauthorized information dissemination.

Affected Version(s)

JeecgBoot 0 <= 3.9.5

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yaqi Chao
.