CVE-2026-75479
Received Received - Intake

Authentication Bypass in JimuReport Exposes Report Data

Vulnerability report for CVE-2026-75479, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-17

Last updated on: 2026-08-17

Assigner: VulnCheck

Description

JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to enumerate all reports and retrieve share tokens. Attackers can use disclosed share tokens to access protected report endpoints and retrieve full report definitions including embedded SQL statements and live query data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-17
Last Modified
2026-08-17
Generated
2026-08-18
AI Q&A
2026-08-18
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JimuReport has an authentication bypass flaw in the report folder template listing endpoint. Unauthenticated attackers can list all reports and obtain share tokens. These tokens allow access to protected report endpoints, exposing full report definitions including embedded SQL statements and live query data.

Detection Guidance

To detect this vulnerability, check if unauthenticated users can access the report folder template listing endpoint. Test by sending a GET request to the endpoint and verifying if report listings or share tokens are returned without authentication.

Impact Analysis

Attackers could steal sensitive data from reports, including SQL queries and live data. This may lead to data breaches, unauthorized access to confidential information, or further exploitation of the system if embedded queries contain credentials or system details.

Compliance Impact

This vulnerability could violate GDPR by exposing personal data or HIPAA by leaking protected health information. Organizations may face fines, legal action, or reputational damage due to non-compliance with data protection requirements.

Mitigation Strategies

Immediately restrict access to the report folder template listing endpoint. Update JimuReport to the latest patched version. Implement network-level controls to block unauthorized access to sensitive endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75479. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart