Authentication Bypass in JimuReport Affects Unauthenticated Access to Reports
CVE-2026-75479

8.7HIGH

Key Information:

Vendor

Jeecgboot

Vendor
CVE Published:
17 August 2026

What is CVE-2026-75479?

JimuReport suffers from an authentication bypass vulnerability, enabling unauthenticated attackers to interact with the report folder template listing endpoint. This flaw allows malicious users to enumerate all available reports, exposing sensitive share tokens that can grant unauthorized access to protected report endpoints. As a result, attackers can retrieve critical information, including full report definitions, embedded SQL statements, and live query data, significantly compromising the integrity and confidentiality of the reports.

Affected Version(s)

jimureport 0 <= 2.3.4

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

geo-chen
.