Improper Access Control Vulnerability in JeecgBoot by Jeecg
CVE-2026-9580
Key Information:
Badges
What is CVE-2026-9580?
A vulnerability has been identified in JeecgBoot versions up to 3.9.1, specifically within the LoginController.selectDepart function. This flaw allows for improper access controls, potentially enabling remote exploitation. The issue has been publicly disclosed, underscoring the urgency for affected users to upgrade to version 3.9.2, where this vulnerability is addressed. Failure to upgrade could expose systems to unauthorized access and manipulation.
Affected Version(s)
JeecgBoot 3.9.0
JeecgBoot 3.9.1
JeecgBoot 3.9.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
