JeecgBoot 在 3.9.5 版本中存在一个授权缺失漏洞,允许低权限的已认证用户通过 DELETE /sys/category/deleteBatch 接口删除分类字典条目。攻击者可以从未受保护的 rootList 和 childList 端点获取节点 ID,并将其提交以递归方式删除整个 sys_category 子树,从而导致相关表单和字典字段依赖关系被破坏。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-108628 | 8.1 HIGH | JeecgBoot through 3.9.5 Missing Authorization via saveDeptRolePermission Endpoint |
| CVE-2026-108657 | 8.1 HIGH | JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/passApply |
| CVE-2026-108623 | 7.1 HIGH | JeecgBoot through 3.9.5 Missing Authorization via /sys/log/deleteBatch |
| CVE-2026-108671 | 6.5 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/airagMcp/queryById |
| CVE-2026-108677 | 6.5 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/api/getUserByName |
| CVE-2026-108661 | 6.5 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/changeOwenUserTenant |
| CVE-2026-108648 | 6.5 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via getDynamicDbSourceByCode Endpoint |
| CVE-2026-108631 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/sysDepartPermission/delete |
| CVE-2026-108622 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/log/delete Endpoint |
| CVE-2026-108634 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via sysDepartPermission deleteBatch Endpoint |
| CVE-2026-108639 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/dict/deletePhysic/{id} |
| CVE-2026-108668 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/deleteRecycleBin |
| CVE-2026-108615 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/extData/delete |
| CVE-2026-108611 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/word/delete Endpoint |
| CVE-2026-108613 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/app/release Endpoint |
| CVE-2026-108666 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/deleteBatch |
| CVE-2026-108619 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via sysMessageTemplate deleteBatch Endpoint |
| CVE-2026-108606 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/ocr/deleteById |
| CVE-2026-108644 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/category/delete |
| CVE-2026-108624 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via sysMessage deleteBatch Endpoint |
Showing top 20 of 76 CVEs. View all on vendor page → →
No comments yet