JeecgBoot 3.9.5 及之前版本中,SysDepartPermissionController 的删除处理程序存在缺失授权验证的漏洞,允许低权限认证用户删除部门权限绑定。攻击者可以通过未受保护的列表接口获取行 ID,并发送包含 id 参数的 DELETE 请求,从而移除部门可为其角色分配的功能菜单或按钮权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-108657 | 8.1 HIGH | JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/passApply |
| CVE-2026-108628 | 8.1 HIGH | JeecgBoot through 3.9.5 Missing Authorization via saveDeptRolePermission Endpoint |
| CVE-2026-108623 | 7.1 HIGH | JeecgBoot through 3.9.5 Missing Authorization via /sys/log/deleteBatch |
| CVE-2026-108671 | 6.5 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/airagMcp/queryById |
| CVE-2026-108648 | 6.5 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via getDynamicDbSourceByCode Endpoint |
| CVE-2026-108677 | 6.5 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/api/getUserByName |
| CVE-2026-108661 | 6.5 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/changeOwenUserTenant |
| CVE-2026-108620 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/position/deleteBatch |
| CVE-2026-108668 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/deleteRecycleBin |
| CVE-2026-108634 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via sysDepartPermission deleteBatch Endpoint |
| CVE-2026-108611 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/word/delete Endpoint |
| CVE-2026-108662 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/deleteTenantPackUser |
| CVE-2026-108624 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via sysMessage deleteBatch Endpoint |
| CVE-2026-108615 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/extData/delete |
| CVE-2026-108613 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/app/release Endpoint |
| CVE-2026-108619 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via sysMessageTemplate deleteBatch Endpoint |
| CVE-2026-108643 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/category/deleteBatch |
| CVE-2026-108666 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/deleteBatch |
| CVE-2026-108606 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/ocr/deleteById |
| CVE-2026-108644 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/category/delete |
Showing top 20 of 76 CVEs. View all on vendor page → →
No comments yet