CVE-2026-108648
Received Received - Intake

JeecgBoot Missing Authorization Exposes Database Credentials

Vulnerability report for CVE-2026-108648, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the GET /sys/api/getDynamicDbSourceByCode endpoint of SystemApiController, which lacks Shiro permission or role annotations. Any authenticated low-privileged user can supply datasource codes in the dbSourceCode parameter to retrieve JDBC URLs, usernames and decrypted cleartext database passwords.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jeecgboot JeecgBoot 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JeecgBoot through version 3.9.5 has a missing authorization vulnerability in the GET /sys/api/getDynamicDbSourceByCode endpoint. This endpoint lacks proper Shiro permission or role annotations, allowing any authenticated low-privileged user to retrieve sensitive database information by supplying datasource codes in the dbSourceCode parameter. The exposed data includes JDBC URLs, usernames, and decrypted cleartext database passwords.

Detection Guidance

To detect this vulnerability, check if the endpoint /sys/api/getDynamicDbSourceByCode is accessible without proper authorization. Use tools like curl to send a GET request with a test dbSourceCode parameter. Example: curl -X GET 'http://<target>/sys/api/getDynamicDbSourceByCode?dbSourceCode=test'

Inspect network traffic for unauthorized access to this endpoint. Review application logs for suspicious requests to /sys/api/getDynamicDbSourceByCode with varying dbSourceCode values.

Impact Analysis

An attacker with low privileges could exploit this vulnerability to gain access to sensitive database credentials and connection details. This could lead to unauthorized data access, data breaches, or further attacks on the database infrastructure. The impact includes potential exposure of sensitive information and compromise of database integrity.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR, HIPAA, and other data protection regulations due to unauthorized access to sensitive data. It may result in data breaches, loss of personal or health information, and failure to meet regulatory requirements for data security and access controls.

Mitigation Strategies

Immediately update JeecgBoot to version 3.9.5 or later to address the missing authorization flaw. Ensure proper Shiro permission or role annotations are applied to the /sys/api/getDynamicDbSourceByCode endpoint.

Restrict access to the vulnerable endpoint by implementing authentication and authorization checks. Audit all database credentials and rotate them if they may have been exposed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108648. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart