CVE-2026-108674
Received Received - Intake

JeecgBoot Missing Authorization in OpenAPI Query Handler

Vulnerability report for CVE-2026-108674, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the OpenApiController queryById handler that allows low-privileged authenticated users to read OpenAPI definitions without openapi permissions. Attackers can request GET /openapi/queryById with an entry id to obtain internal origin URLs, virtual paths, IP whitelists, and header and parameter templates.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jeecgboot JeecgBoot 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JeecgBoot through version 3.9.5 has a missing authorization vulnerability in the OpenApiController queryById handler. This flaw allows low-privileged authenticated users to access OpenAPI definitions without proper permissions. Attackers can exploit this by sending a GET request to /openapi/queryById with an entry ID to retrieve sensitive details like internal URLs, virtual paths, IP whitelists, and header or parameter templates.

Detection Guidance

To detect this vulnerability, check if unauthenticated or low-privileged users can access OpenAPI definitions via GET requests to /openapi/queryById. Use tools like curl to test endpoints: curl -X GET http://<target>/openapi/queryById?id=<entry_id>. If sensitive data like internal URLs or IP whitelists is returned, the system is vulnerable.

Impact Analysis

This vulnerability could allow unauthorized users to gather internal system information, potentially exposing network architecture, security configurations, and sensitive endpoints. Attackers might use this data to plan further attacks, such as data breaches or service disruptions, by identifying weak points in the system.

Compliance Impact

This vulnerability allows low-privileged users to access internal OpenAPI definitions, including origin URLs, virtual paths, IP whitelists, and header templates. Such unauthorized access could expose sensitive system information, potentially violating data protection requirements under GDPR (e.g., Article 32 on security of processing) and HIPAA (e.g., safeguards for protected health information).

Mitigation Strategies

Immediately update JeecgBoot to version 3.9.6 or later. If an update is not possible, restrict access to the /openapi/queryById endpoint using network-level controls or web application firewalls. Ensure proper authentication and authorization checks are enforced for all API endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108674. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart