CVE-2026-108643
Received Received - Intake

JeecgBoot Missing Authorization Leading to Category Deletion

Vulnerability report for CVE-2026-108643, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to delete category dictionary entries via DELETE /sys/category/deleteBatch. Attackers can obtain node ids from the unguarded rootList and childList endpoints and submit them to recursively delete entire sys_category subtrees, breaking dependent forms and dictionary fields.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jeecgboot JeecgBoot 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JeecgBoot through version 3.9.5 has a missing authorization vulnerability. Low-privileged authenticated users can delete category dictionary entries by sending a DELETE request to /sys/category/deleteBatch. Attackers can gather node IDs from unprotected endpoints (rootList and childList) and use them to recursively delete entire sys_category subtrees, which can break dependent forms and dictionary fields.

Detection Guidance

Check for unauthorized DELETE requests to /sys/category/deleteBatch. Monitor for missing authorization errors in logs. Verify if low-privileged users can access rootList or childList endpoints to obtain node IDs.

Impact Analysis

This vulnerability allows attackers with low privileges to delete critical data, including dictionary entries and form dependencies. This can disrupt system functionality, cause data loss, and require costly recovery efforts. It may also lead to unauthorized modifications affecting application behavior.

Compliance Impact

This vulnerability could lead to unauthorized data deletion or modification, violating integrity and availability requirements in GDPR and HIPAA. It may result in non-compliance due to potential data loss, lack of access controls, and inability to maintain accurate records, leading to legal and financial penalties.

Mitigation Strategies

Apply patches or updates to JeecgBoot version 3.9.5 or later. Restrict DELETE /sys/category/deleteBatch access to authorized roles only. Implement input validation to prevent node ID enumeration.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108643. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart