CVE-2026-108653
Received Received - Intake

JeecgBoot Missing Authorization in OpenAPI Registry Query

Vulnerability report for CVE-2026-108653, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the queryPageList handler of OpenApiController that allows any authenticated user to list OpenAPI registry definitions. Low-privileged attackers can query GET /openapi/list to read virtual paths, internal origin URLs, IP whitelists, and header and parameter templates intended for administrators.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jeecgboot JeecgBoot 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JeecgBoot through version 3.9.5 has a missing authorization vulnerability in the OpenApiController's queryPageList handler. This flaw allows any authenticated user, even with low privileges, to list OpenAPI registry definitions by querying GET /openapi/list. Attackers can access sensitive information such as virtual paths, internal origin URLs, IP whitelists, and header and parameter templates that are meant for administrators only.

Detection Guidance

Check for unauthorized access to the OpenAPI endpoint by monitoring GET requests to /openapi/list. Look for unusual activity from low-privileged users or unexpected data exposure in logs.

Impact Analysis

An attacker could exploit this to gather internal system details, such as internal URLs and IP whitelists, which may aid further attacks. This could lead to unauthorized access to sensitive data or systems if combined with other vulnerabilities. The impact is limited to information disclosure since no direct modification or deletion of data is possible.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR's data protection principles or HIPAA's security requirements for protected health information. Organizations may face compliance violations if exposed data includes personal or health-related information.

Mitigation Strategies

Update JeecgBoot to the latest version beyond 3.9.5. Restrict access to the /openapi/list endpoint by implementing proper authorization checks. Review and audit API access logs for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108653. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart