Authorization Bypass in Jeepay from Jeequan
CVE-2026-18631
Key Information:
Badges
What is CVE-2026-18631?
A vulnerability in the Jeepay software by Jeequan allows for an authorization bypass due to inadequate safeguards in the WebSecurityConfig functionality. Specifically, this flaw lies within the SysLogController.java file, enabling attackers to manipulate access controls and potentially gain unauthorized entry into restricted areas of the application. The issue can be exploited remotely, and due to the availability of the exploit on public platforms, it poses a significant risk to users still operating on versions up to 3.2.9. The vendor has been informed of the issue but has not provided any feedback or patches to address the risk.
Affected Version(s)
jeepay 3.2.0
jeepay 3.2.1
jeepay 3.2.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
