Authentication Bypass in JimuReport Affects Unauthenticated Access to Reports
CVE-2026-75479
8.7HIGH
What is CVE-2026-75479?
JimuReport suffers from an authentication bypass vulnerability, enabling unauthenticated attackers to interact with the report folder template listing endpoint. This flaw allows malicious users to enumerate all available reports, exposing sensitive share tokens that can grant unauthorized access to protected report endpoints. As a result, attackers can retrieve critical information, including full report definitions, embedded SQL statements, and live query data, significantly compromising the integrity and confidentiality of the reports.
Affected Version(s)
jimureport 0 <= 2.3.4
