JeecgBoot 3.9.5 及之前版本中存在一个授权缺失漏洞,具体位于 SysDepartRoleController 的 queryById 处理方法中,该处理程序缺少 Shiro 权限注解。低权限的已认证攻击者可以通过向 /sys/sysDepartRole/queryById 发起 GET 请求,并传入任意 id,从而读取部门角色的名称、编码、描述以及审计字段信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-108628 | 8.1 HIGH | JeecgBoot through 3.9.5 Missing Authorization via saveDeptRolePermission Endpoint |
| CVE-2026-108657 | 8.1 HIGH | JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/passApply |
| CVE-2026-108623 | 7.1 HIGH | JeecgBoot through 3.9.5 Missing Authorization via /sys/log/deleteBatch |
| CVE-2026-108671 | 6.5 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/airagMcp/queryById |
| CVE-2026-108677 | 6.5 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/api/getUserByName |
| CVE-2026-108661 | 6.5 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/changeOwenUserTenant |
| CVE-2026-108648 | 6.5 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via getDynamicDbSourceByCode Endpoint |
| CVE-2026-108612 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/word/deleteBatch |
| CVE-2026-108616 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/extData/deleteBatch |
| CVE-2026-108622 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/log/delete Endpoint |
| CVE-2026-108615 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/extData/delete |
| CVE-2026-108611 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/word/delete Endpoint |
| CVE-2026-108643 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/category/deleteBatch |
| CVE-2026-108666 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/deleteBatch |
| CVE-2026-108624 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via sysMessage deleteBatch Endpoint |
| CVE-2026-108613 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/app/release Endpoint |
| CVE-2026-108619 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via sysMessageTemplate deleteBatch Endpoint |
| CVE-2026-108606 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/ocr/deleteById |
| CVE-2026-108644 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/category/delete |
| CVE-2026-108668 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/deleteRecycleBin |
Showing top 20 of 76 CVEs. View all on vendor page → →
No comments yet