Missing Authorization Vulnerability in JeecgBoot Product
CVE-2026-108870
Key Information:
Badges
What is CVE-2026-108870?
JeecgBoot version 3.9.5 contains a vulnerability within the SysRoleController's saveDatarule handler. This flaw enables low-privileged authenticated users to alter role data rules without proper authorization. Attackers can exploit this by sending specific parameters such as permissionId, roleId, and dataRuleIds, which may lead to the unchecked modification of data_rule_ids. As a result, row-level filters could be bypassed, allowing wider access to sensitive data or manipulation of filtering settings for other roles.
Affected Version(s)
JeecgBoot 0 <= 3.9.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
