CVE-2026-108671
Received Received - Intake

JeecgBoot Missing Authorization Exposes MCP Server Configs

Vulnerability report for CVE-2026-108671, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to read MCP server configurations because the queryById permission check is commented out. Attackers can obtain record ids from the unguarded /airag/app/queryById endpoint and retrieve MCP endpoint URLs, headers, and outbound authentication tokens.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jeecgboot JeecgBoot 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JeecgBoot through version 3.9.5 has a missing authorization vulnerability where the permission check for queryById is disabled. This allows any authenticated user to read MCP server configurations by exploiting the unprotected /airag/app/queryById endpoint. Attackers can retrieve sensitive details like MCP endpoint URLs, headers, and outbound authentication tokens by obtaining record IDs from this endpoint.

Detection Guidance

Check JeecgBoot application logs for repeated access to /airag/app/queryById endpoints. Inspect network traffic for unauthorized MCP server configuration requests. Verify if any user accounts have accessed configuration data without proper permissions.

Impact Analysis

This vulnerability allows unauthorized users to access sensitive MCP server configurations, potentially exposing confidential data such as endpoint URLs, headers, and authentication tokens. Attackers could use this information to further compromise systems, exfiltrate data, or launch additional attacks against the MCP server infrastructure.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to unauthorized access to sensitive data. GDPR requires protection of personal data, while HIPAA mandates safeguards for protected health information. A breach via this vulnerability may result in data exposure, violating these regulations and potentially leading to legal penalties or fines.

Mitigation Strategies

Upgrade JeecgBoot to version 3.9.6 or later. Remove the commented-out permission check in the queryById endpoint. Implement strict access controls and audit all MCP server configurations for unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108671. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart