CVE-2026-108672
Received Received - Intake

JeecgBoot Authorization Bypass Exposes User Video Records

Vulnerability report for CVE-2026-108672, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

JeecgBoot through 3.9.5 contains an authorization bypass vulnerability in the getVideoRecords handler of VideoGenerationController that allows authenticated users to read other users' records via the userId parameter. Low-privileged attackers can supply another user id to retrieve their AI video generation history, including prompts, task ids, video URLs and cover URLs.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jeecgboot JeecgBoot 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JeecgBoot through version 3.9.5 has an authorization bypass flaw in the VideoGenerationController's getVideoRecords handler. Authenticated users can exploit the userId parameter to access other users' AI video generation records, including prompts, task IDs, video URLs, and cover URLs.

Detection Guidance

To detect this vulnerability, check if your JeecgBoot application (version 3.9.5 or earlier) has the VideoGenerationController endpoint exposed. Look for requests to /getVideoRecords with a userId parameter that returns data not belonging to the authenticated user. Monitor logs for unauthorized access patterns or unusual data retrievals.

Impact Analysis

Low-privileged attackers could retrieve sensitive AI video generation data belonging to other users. This includes proprietary prompts, generated video content, and associated metadata, potentially leading to data leaks or misuse of personal information.

Compliance Impact

This vulnerability could violate data protection regulations like GDPR and HIPAA by enabling unauthorized access to personal and sensitive data. Organizations using JeecgBoot may face compliance breaches, legal penalties, and reputational damage due to exposed user records.

Mitigation Strategies

Immediately update JeecgBoot to a version beyond 3.9.5 to patch the authorization bypass. If an update is not available, restrict access to the /getVideoRecords endpoint and validate that the userId parameter matches the authenticated user's ID before processing requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108672. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart