CVE-2026-108872
Received Received - Intake

JeecgBoot Missing Authorization in SysUserController

Vulnerability report for CVE-2026-108872, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the batchEditUsers handler of SysUserController that allows any authenticated user to edit user department assignments. Low-privileged attackers can send PUT requests to /sys/user/batchEditUsers with arbitrary user and department ids to move users, including administrators, between departments and overwrite positions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jeecgboot JeecgBoot 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JeecgBoot through 3.9.5 has a missing authorization vulnerability in the batchEditUsers handler of SysUserController. Any authenticated user can send PUT requests to /sys/user/batchEditUsers with arbitrary user and department IDs to edit user department assignments. This allows low-privileged attackers to move users, including administrators, between departments and overwrite positions.

Detection Guidance

To detect this vulnerability, monitor for PUT requests to /sys/user/batchEditUsers with arbitrary user and department IDs. Check logs for unauthorized department changes or position overwrites. Use network monitoring tools to inspect HTTP PUT requests targeting this endpoint.

Impact Analysis

An attacker could escalate privileges by moving administrators to different departments, manipulate user roles or permissions, or disrupt organizational structure. Unauthorized department changes may lead to data access issues or compliance violations. The vulnerability enables privilege escalation without requiring high-level access.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles or HIPAA's access controls. Unauthorized user role changes may result in improper data handling, potentially causing compliance breaches. Organizations using JeecgBoot must address this to maintain regulatory compliance.

Mitigation Strategies

Immediately update JeecgBoot to a version beyond 3.9.5. Implement strict input validation for user and department IDs in the batchEditUsers endpoint. Restrict PUT requests to /sys/user/batchEditUsers to authorized roles only. Review logs for signs of exploitation and revoke unauthorized department changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108872. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart