JeecgBoot 在 3.9.5 及之前版本中存在一个权限控制缺失漏洞。该漏洞允许低权限的已认证用户通过调用 PUT /sys/message/sysMessage/edit 接口,修改消息推送记录。攻击者可以构造请求,指定任意 sys_sms 记录的 ID,从而覆盖其标题、内容、接收者地址和发送状态,而系统未进行所有权校验。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-108657 | 8.1 HIGH | JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/passApply |
| CVE-2026-108628 | 8.1 HIGH | JeecgBoot through 3.9.5 Missing Authorization via saveDeptRolePermission Endpoint |
| CVE-2026-108623 | 7.1 HIGH | JeecgBoot through 3.9.5 Missing Authorization via /sys/log/deleteBatch |
| CVE-2026-108671 | 6.5 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/airagMcp/queryById |
| CVE-2026-108648 | 6.5 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via getDynamicDbSourceByCode Endpoint |
| CVE-2026-108677 | 6.5 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/api/getUserByName |
| CVE-2026-108661 | 6.5 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/changeOwenUserTenant |
| CVE-2026-108622 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/log/delete Endpoint |
| CVE-2026-108631 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/sysDepartPermission/delete |
| CVE-2026-108662 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/deleteTenantPackUser |
| CVE-2026-108634 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via sysDepartPermission deleteBatch Endpoint |
| CVE-2026-108624 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via sysMessage deleteBatch Endpoint |
| CVE-2026-108668 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/deleteRecycleBin |
| CVE-2026-108615 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/extData/delete |
| CVE-2026-108613 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/app/release Endpoint |
| CVE-2026-108619 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via sysMessageTemplate deleteBatch Endpoint |
| CVE-2026-108643 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/category/deleteBatch |
| CVE-2026-108666 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/deleteBatch |
| CVE-2026-108606 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/ocr/deleteById |
| CVE-2026-108644 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/category/delete |
Showing top 20 of 76 CVEs. View all on vendor page → →
No comments yet