Improper Access Control in JeecgBoot Affecting User Management Features
CVE-2026-9579
Key Information:
Badges
What is CVE-2026-9579?
A security vulnerability has been identified in JeecgBoot versions up to 3.9.1, specifically within the user management function located in the SysUser component. The flaw resides in the user.getUsername method, where the argument userIdentity can be manipulated, leading to improper access controls. This vulnerability allows unauthorized users to potentially gain access to sensitive information or perform unauthorized actions. The vulnerability can be exploited remotely, posing a significant risk to organizations using this software. It is strongly recommended to upgrade to version 3.9.2 to mitigate this issue and enhance security protocols.
Affected Version(s)
JeecgBoot 3.9.0
JeecgBoot 3.9.1
JeecgBoot 3.9.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
