CVE-2026-108617
Received Received - Intake

Missing Authorization in JeecgBoot Allows Template Creation

Vulnerability report for CVE-2026-108617, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to create message templates by calling POST /sys/message/sysMessageTemplate/add. Attackers holding only minimal roles can insert arbitrary notification templates with chosen codes and content into the shared sys_sms_template library used for system, e-mail, SMS and IM notifications.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jeecgboot JeecgBoot 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JeecgBoot through version 3.9.5 has a missing authorization vulnerability. Low-privileged authenticated users can create message templates by sending a POST request to /sys/message/sysMessageTemplate/add. This allows attackers with minimal roles to insert arbitrary notification templates into the shared sys_sms_template library, which is used for system, email, SMS, and IM notifications.

Detection Guidance

Check for unauthorized POST requests to /sys/message/sysMessageTemplate/add by reviewing web server or application logs for suspicious activity. Look for low-privileged users creating or modifying message templates.

Impact Analysis

An attacker could exploit this to inject malicious or misleading notification templates into the system. This could lead to unauthorized messages being sent to users, potentially spreading misinformation, phishing attempts, or disrupting normal system operations. The impact depends on how the system uses these templates for notifications.

Compliance Impact

This vulnerability could lead to unauthorized data exposure or manipulation of notifications, which may violate compliance requirements under GDPR (data protection) or HIPAA (health information privacy). Unauthorized message content could result in breaches of confidentiality or integrity, potentially leading to regulatory penalties.

Mitigation Strategies

Update JeecgBoot to version 3.9.5 or later. Restrict access to the /sys/message/sysMessageTemplate/add endpoint by implementing proper authorization checks. Audit existing message templates for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108617. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart