Missing Authorization in JeecgBoot Export Functionality Affects User Role Management
CVE-2026-108888
Key Information:
Badges
What is CVE-2026-108888?
JeecgBoot version 3.9.5 is impacted by a missing authorization vulnerability within the SysDepartRoleController's exportXls handler. This flaw enables any authenticated user, including those with minimal privileges, to exploit the /sys/sysDepartRole/exportXls endpoint. As a result, they can download sensitive data related to department roles—such as names, codes, descriptions, and the identities of users who created them—without proper access controls in place. This vulnerability poses significant risks to the confidentiality of role management within affected systems.
Affected Version(s)
JeecgBoot 0 <= 3.9.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
