CVE-2026-108642
Received Received - Intake

Authenticated Users Can Modify Message Delivery Records in JeecgBoot

Vulnerability report for CVE-2026-108642, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in SysAnnouncementSendController that allows authenticated users to modify other users' message delivery records. Attackers can obtain delivery ids from GET /sys/sysAnnouncementSend/list and submit edit requests that overwrite read flags, recipient ids, or linked announcements to hide messages from recipients.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jeecgboot JeecgBoot 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JeecgBoot through version 3.9.5 has a missing authorization vulnerability in the SysAnnouncementSendController. Authenticated users can exploit this to modify other users' message delivery records by obtaining delivery IDs from a list endpoint and submitting edit requests. This allows attackers to change read flags, recipient IDs, or linked announcements to hide messages from recipients.

Detection Guidance

To detect this vulnerability, monitor for unauthorized modifications to message delivery records in JeecgBoot systems. Check for suspicious GET requests to /sys/sysAnnouncementSend/list followed by POST/PUT requests to edit delivery records. Review logs for unusual activity where authenticated users alter read flags, recipient IDs, or linked announcements.

Impact Analysis

If you use JeecgBoot versions up to 3.9.5, an attacker with valid credentials could alter your message delivery records. This could lead to messages being marked as unread, redirected, or hidden, potentially causing missed communications or unauthorized access to sensitive information.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized modification of message records, which may violate data integrity and confidentiality requirements under GDPR and HIPAA. Organizations using affected versions may face compliance risks due to potential unauthorized access or tampering with sensitive data.

Mitigation Strategies

Immediately update JeecgBoot to version 3.9.5 or later to patch the missing authorization flaw. Implement strict access controls to restrict authenticated users from modifying delivery records. Review and audit existing message delivery records for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108642. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart