CVE-2026-108875
Received Received - Intake

JeecgBoot Missing Authorization in SysUserController

Vulnerability report for CVE-2026-108875, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysUserController addSysUserGroup handler that allows any authenticated user to modify user group membership. Low-privileged attackers can send POST requests with arbitrary user ids and a groupId to add any users to administrator-maintained groups without permission checks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jeecgboot JeecgBoot 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JeecgBoot through version 3.9.5 has a missing authorization vulnerability in the SysUserController addSysUserGroup handler. This allows any authenticated user to modify user group membership without proper permission checks. Low-privileged attackers can send POST requests with arbitrary user IDs and a group ID to add users to administrator-maintained groups.

Detection Guidance

To detect this vulnerability, check if the endpoint /sys/user/addSysUserGroup is accessible without proper authorization. Use tools like curl to send a POST request with arbitrary user IDs and group IDs to see if the system allows unauthorized group membership modifications. Example: curl -X POST -d 'userIds=1&groupId=1' http://target.com/sys/user/addSysUserGroup

Verify if the endpoint lacks @RequiresPermissions or @RequiresRoles annotations. Check server logs for unauthorized POST requests to this endpoint.

Impact Analysis

This vulnerability allows unauthorized users to add themselves or others to privileged groups, potentially gaining elevated access. Attackers could escalate privileges, access sensitive data, or perform administrative actions without proper authorization.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data by allowing low-privileged users to modify group memberships, potentially granting excessive permissions. This may violate compliance requirements under GDPR (data protection) and HIPAA (healthcare data privacy) by enabling unauthorized access to personal or protected health information.

Mitigation Strategies

Immediately update JeecgBoot to a version beyond 3.9.5 if available. If not, restrict access to the /sys/user/addSysUserGroup endpoint via firewall rules or web application firewall (WAF).

Implement proper authorization checks in the endpoint handler, such as adding @RequiresPermissions or @RequiresRoles annotations. Monitor logs for suspicious POST requests to this endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108875. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart