CVE-2026-108649
Received Received - Intake

JeecgBoot Missing Authorization in SystemApiController

Vulnerability report for CVE-2026-108649, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the queryUserRolesById handler of SystemApiController that lets authenticated users read any user's role codes. Low-privileged attackers can send a userId to GET /sys/api/queryUserRolesById to enumerate role assignments and identify administrator accounts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jeecgboot JeecgBoot 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JeecgBoot through version 3.9.5 has a missing authorization vulnerability in the SystemApiController's queryUserRolesById handler. This flaw allows authenticated users to read any user's role codes by sending a userId to the GET endpoint /sys/api/queryUserRolesById. Low-privileged attackers can exploit this to enumerate role assignments and identify administrator accounts.

Detection Guidance

Check for unauthorized access to /sys/api/queryUserRolesById by monitoring GET requests with userId parameters. Look for repeated requests to this endpoint from low-privileged accounts.

Impact Analysis

This vulnerability allows attackers with low privileges to gain unauthorized access to sensitive role information. They can identify administrator accounts, which may lead to privilege escalation attacks. Attackers could use this information to target high-value accounts for further exploitation, such as phishing or lateral movement within the system.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA by exposing sensitive user role data, which may include personally identifiable information or protected health information. Unauthorized access to role assignments violates data protection principles, potentially resulting in regulatory fines and reputational damage.

Mitigation Strategies

Update JeecgBoot to version 3.9.5 or later. Restrict access to /sys/api/queryUserRolesById by implementing proper authorization checks. Review logs for suspicious activity targeting this endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108649. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart