CVE-2026-108635
Received Received - Intake

JeecgBoot Missing Authorization Exposes Staff Data

Vulnerability report for CVE-2026-108635, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the GET /sys/sysDepart/getDepartmentHead endpoint of SysDepartController that allows any authenticated user to list department staff. Low-privileged attackers can enumerate departId values to retrieve staff names, avatars, posts, and mobile and telephone numbers, including contacts marked hidden.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jeecgboot JeecgBoot 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JeecgBoot through version 3.9.5 has a missing authorization vulnerability in the GET /sys/sysDepart/getDepartmentHead endpoint. This flaw allows any authenticated user, even with low privileges, to list department staff by enumerating departId values. Attackers can retrieve sensitive staff information such as names, avatars, posts, mobile numbers, and telephone numbers, including contacts marked as hidden.

Detection Guidance

To detect this vulnerability, check for unauthorized access to the GET /sys/sysDepart/getDepartmentHead endpoint. Monitor logs for repeated requests to this path with varying departId values. Use tools like curl to test the endpoint manually: curl -X GET 'http://<target>/sys/sysDepart/getDepartmentHead?departId=<value>' and observe if it returns staff details without proper authorization.

Impact Analysis

This vulnerability enables unauthorized users to access and collect personal and contact details of department staff. Attackers could use this data for phishing, social engineering, or further targeted attacks. Organizations may face reputational damage, loss of trust, and potential legal consequences due to unauthorized data exposure.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA by exposing personal data without proper authorization. GDPR requires strict access controls and data protection measures, while HIPAA mandates safeguards for protected health information. Non-compliance could result in significant fines and legal penalties.

Mitigation Strategies

Immediately restrict access to the /sys/sysDepart/getDepartmentHead endpoint by implementing proper authorization checks. Update JeecgBoot to the latest version beyond 3.9.5. Review and audit user permissions to ensure low-privileged users cannot access sensitive endpoints. Consider blocking or monitoring requests to this path in your web application firewall.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108635. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart