Missing Authorization in JeecgBoot Product by Jeecg
CVE-2026-108874
Key Information:
Badges
What is CVE-2026-108874?
The JeecgBoot application, specifically in version 3.9.5, has a flaw where limited privilege authenticated users can manipulate user roles related to department management. By exploiting the PUT method on the endpoint /sys/user/changeDepartChargePerson, attackers can gain the ability to appoint or dismiss department heads. This vulnerability allows attackers to change department head assignments by providing any user ID, department ID, and status values, ultimately increasing the risk of unauthorized access to sensitive department views and positions.
Affected Version(s)
JeecgBoot 0 <= 3.9.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
