CVE-2026-108869
Received Received - Intake

Missing Authorization in JeecgBoot Allows Forged System Announcements

Vulnerability report for CVE-2026-108869, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to send system announcements by calling POST /sys/api/sendSysAnnouncement. Attackers can supply arbitrary title, content, fromUser and toUser values to deliver forged announcements to any users via WebSocket, WeCom, DingTalk and Feishu.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jeecgboot JeecgBoot 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-108869 is a missing authorization vulnerability in JeecgBoot through version 3.9.5. It allows low-privileged authenticated users to send system announcements via the POST /sys/api/sendSysAnnouncement endpoint. Attackers can manipulate title, content, sender, and recipient values to forge announcements delivered through WebSocket, WeCom, DingTalk, and Feishu.

Detection Guidance

Check for unauthorized POST requests to /sys/api/sendSysAnnouncement. Monitor WebSocket, WeCom, DingTalk, and Feishu channels for unexpected system announcements. Review logs for HTTP 200 responses with database errors or truncated title fields.

Impact Analysis

This vulnerability enables attackers to send fake system announcements to any users, potentially tricking them into taking harmful actions. It could lead to misinformation, phishing attacks, or unauthorized data exposure if announcements contain malicious links or instructions.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling unauthorized data access or manipulation. Low-privileged users could send forged system announcements to any users, potentially exposing sensitive data or misleading recipients. GDPR requires protecting personal data integrity and confidentiality, while HIPAA mandates access controls for protected health information. The lack of authorization checks may violate these requirements by allowing unauthorized actions.

Mitigation Strategies

Upgrade JeecgBoot to a version beyond 3.9.5. Implement strict input validation for API endpoints. Add authorization checks using @RequiresPermissions annotations. Restrict access to /sys/api paths.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108869. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart