CVE-2026-108624
Received Received - Intake

JeecgBoot Missing Authorization in SysMessageController

Vulnerability report for CVE-2026-108624, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysMessageController deleteBatch handler that allows low-privileged authenticated users to delete message records. Attackers can obtain record ids from the unguarded list endpoint and submit them to deleteBatch to remove any message push records, including pending queued messages.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jeecgboot JeecgBoot 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JeecgBoot through version 3.9.5 has a missing authorization vulnerability in the SysMessageController deleteBatch handler. This flaw allows low-privileged authenticated users to delete message records without proper authorization checks. Attackers can exploit this by obtaining record IDs from an unprotected list endpoint and submitting them to the deleteBatch function to remove any message push records, including pending queued messages.

Detection Guidance

Detecting this vulnerability involves checking for unauthorized deletions of message records in JeecgBoot systems. Monitor logs for DELETE requests to SysMessageController deleteBatch endpoint by low-privileged users. Verify if users can access message records without proper authorization checks.

Impact Analysis

This vulnerability allows unauthorized users to delete important message records, potentially causing loss of critical communications or data. It could disrupt workflows, lead to missed notifications, or compromise the integrity of message queues. The impact is higher for systems relying on message pushes for operations.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized deletion of message records, which may include sensitive data. For GDPR, this could violate data integrity and accountability principles. For HIPAA, it might compromise protected health information integrity. Organizations may face compliance violations if such unauthorized deletions occur.

Mitigation Strategies

Immediately update JeecgBoot to version 3.9.5 or later. Implement strict access controls to ensure only authorized users can delete message records. Review and restrict permissions for the SysMessageController endpoints to prevent unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108624. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart