CVE-2026-108640
Received Received - Intake

JeecgBoot Missing Authorization in SysDepartRoleController

Vulnerability report for CVE-2026-108640, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysDepartRoleController queryById handler that lacks Shiro permission annotations. Low-privileged authenticated attackers can request GET /sys/sysDepartRole/queryById with any id to read department role names, codes, descriptions and audit fields.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jeecgboot JeecgBoot 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JeecgBoot through version 3.9.5 has a missing authorization vulnerability in the SysDepartRoleController queryById handler. This means the handler does not have proper Shiro permission annotations to restrict access. Low-privileged authenticated attackers can exploit this by sending a GET request to /sys/sysDepartRole/queryById with any id parameter to retrieve sensitive department role information including names, codes, descriptions, and audit fields.

Detection Guidance

To detect this vulnerability, check for unauthorized access to GET /sys/sysDepartRole/queryById endpoints. Monitor logs for requests with any id parameter to this path. Use tools like curl to test if the endpoint leaks department role data without proper authorization.

Impact Analysis

This vulnerability allows attackers with low privileges to access sensitive organizational data such as department role names, codes, descriptions, and audit information. This could lead to unauthorized information disclosure, potential data breaches, and compromise of internal role structures within the affected system.

Compliance Impact

This vulnerability allows low-privileged attackers to read sensitive department role information including names, codes, and descriptions. This could lead to unauthorized access to internal data, potentially violating confidentiality requirements in GDPR and HIPAA if such data includes personal or protected health information.

Mitigation Strategies

Immediately apply the latest patch for JeecgBoot 3.9.5 or later. If patching is not possible, restrict access to the /sys/sysDepartRole/queryById endpoint via network controls or web application firewall rules. Ensure Shiro permission annotations are added to enforce proper authorization checks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108640. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart