CVE-2026-108630
Received Received - Intake

JeecgBoot Missing Authorization in SysDepartPermissionController

Vulnerability report for CVE-2026-108630, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in SysDepartPermissionController that allows any authenticated user to modify department permission records by calling the edit endpoint. Low-privileged attackers can obtain row ids from the unguarded list endpoint and overwrite depart_id, permission_id and data_rule_ids to alter which menus and data rules departments may delegate.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jeecgboot JeecgBoot 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JeecgBoot through version 3.9.5 has a missing authorization vulnerability in the SysDepartPermissionController. This flaw allows any authenticated user to modify department permission records by accessing the edit endpoint. Attackers with low privileges can retrieve row IDs from the unprotected list endpoint and change values like depart_id, permission_id, and data_rule_ids to alter which menus and data rules departments can delegate.

Detection Guidance

Check for unauthorized modifications to department permissions in JeecgBoot by inspecting SysDepartPermissionController endpoints. Look for requests to /edit with depart_id, permission_id, or data_rule_ids parameters from low-privileged users. Monitor logs for unusual PUT or POST requests to /sysDepartPermission/edit.

Impact Analysis

Low-privileged attackers could gain unauthorized access to modify department permissions, potentially allowing them to escalate privileges, access restricted data, or manipulate system configurations. This could lead to unauthorized data exposure or system misuse.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating compliance requirements for data protection and access control in standards like GDPR and HIPAA. It may result in data breaches or unauthorized disclosures, triggering legal and regulatory penalties.

Mitigation Strategies

Upgrade JeecgBoot to version 3.9.6 or later. Apply strict access controls to SysDepartPermissionController endpoints. Restrict PUT/POST requests to /sysDepartPermission/edit to authorized roles only. Review and audit existing department permissions for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108630. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart