JeecgBoot 版本 3.9.5 及之前存在一个授权缺失漏洞,位于 的 处理方法中。该漏洞允许任何已认证的用户拒绝租户管理员的申请。低权限攻击者可以发送带有指定 、 和 参数的 PUT 请求,从而删除任意租户中的待处理申请,并通知申请人申请被拒绝。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-108628 | 8.1 HIGH | JeecgBoot through 3.9.5 Missing Authorization via saveDeptRolePermission Endpoint |
| CVE-2026-108657 | 8.1 HIGH | JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/passApply |
| CVE-2026-108623 | 7.1 HIGH | JeecgBoot through 3.9.5 Missing Authorization via /sys/log/deleteBatch |
| CVE-2026-108671 | 6.5 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/airagMcp/queryById |
| CVE-2026-108677 | 6.5 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/api/getUserByName |
| CVE-2026-108661 | 6.5 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/changeOwenUserTenant |
| CVE-2026-108648 | 6.5 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via getDynamicDbSourceByCode Endpoint |
| CVE-2026-108611 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/word/delete Endpoint |
| CVE-2026-108668 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/deleteRecycleBin |
| CVE-2026-108624 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via sysMessage deleteBatch Endpoint |
| CVE-2026-108620 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/position/deleteBatch |
| CVE-2026-108616 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/extData/deleteBatch |
| CVE-2026-108612 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/word/deleteBatch |
| CVE-2026-108639 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/dict/deletePhysic/{id} |
| CVE-2026-108606 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/ocr/deleteById |
| CVE-2026-108619 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via sysMessageTemplate deleteBatch Endpoint |
| CVE-2026-108666 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/deleteBatch |
| CVE-2026-108643 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/category/deleteBatch |
| CVE-2026-108613 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /airag/app/release Endpoint |
| CVE-2026-108644 | 5.4 MEDIUM | JeecgBoot through 3.9.5 Missing Authorization via /sys/category/delete |
Showing top 20 of 76 CVEs. View all on vendor page → →
No comments yet