JeecgBoot 在版本 3.9.5 及之前版本中,SysLogController 的 deleteBatch 处理程序存在权限校验缺失漏洞,导致任何已认证用户均可删除系统审计日志记录。低权限攻击者可发送一个 DELETE 请求,并将 ids 参数设置为“allclear”,从而清空整个 sys_log 表,抹除所有用户的审计痕迹。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-108657 | 8.1 HIGH | JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/passApply |
| CVE-2026-108628 | 8.1 HIGH | JeecgBoot through 3.9.5 Missing Authorization via saveDeptRolePermission Endpoint |
| CVE-2026-108661 | 6.5 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/changeOwenUserTenant |
| CVE-2026-108677 | 6.5 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/api/getUserByName |
| CVE-2026-108671 | 6.5 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/airagMcp/queryById |
| CVE-2026-108648 | 6.5 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via getDynamicDbSourceByCode Endpoint |
| CVE-2026-108620 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/position/deleteBatch |
| CVE-2026-108634 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via sysDepartPermission deleteBatch Endpoint |
| CVE-2026-108612 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/word/deleteBatch |
| CVE-2026-108662 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/deleteTenantPackUser |
| CVE-2026-108624 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via sysMessage deleteBatch Endpoint |
| CVE-2026-108631 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/sysDepartPermission/delete |
| CVE-2026-108606 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/ocr/deleteById |
| CVE-2026-108619 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via sysMessageTemplate deleteBatch Endpoint |
| CVE-2026-108615 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/extData/delete |
| CVE-2026-108611 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/word/delete Endpoint |
| CVE-2026-108613 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/app/release Endpoint |
| CVE-2026-108643 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/category/deleteBatch |
| CVE-2026-108666 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/deleteBatch |
| CVE-2026-108644 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/category/delete |
Showing top 20 of 76 CVEs. View all on vendor page → →
No comments yet