Sceawere

Vulnerability Detail

CVE-2026-108866UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

JeecgBoot Missing Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
jeecgboot
Product
JeecgBoot
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows authenticated users to read any account's permissions via the queryUserAuths handler. Low-privileged attackers can supply an arbitrary userId parameter to retrieve another user's complete permission set and identify administrator accounts.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-11T15:16:53.110Z",
  "pubdate": "2026-10-11T15:16:53.110Z",
  "executiveSummary": "JeecgBoot versions up to and including 3.9.5 are susceptible to a critical missing authorization vulnerability residing within the system's user permission management interface.\nThe vulnerability type is classified as an Insecure Direct Object Reference (IDOR) or a missing function-level access control failure, allowing authenticated users to bypass intended authorization boundaries.\nBy manipulating the userId parameter within the queryUserAuths handler, an attacker can access sensitive security configurations and permission structures belonging to any user in the system, including administrative accounts.\nThe impact is significant, as it facilitates privilege escalation, reconnaissance, and unauthorized information disclosure regarding the system's security architecture.\nExploitation requires a valid user session, but no elevated privileges are necessary; the vulnerability permits low-privileged users to enumerate authorization scopes across the entire application domain.\nThis flaw poses a severe risk to organizational confidentiality, potentially enabling attackers to identify high-value targets or accounts with administrative oversight, thereby undermining the integrity of the role-based access control (RBAC) model employed by the platform.",
  "technicalDetails": "The vulnerability is rooted in an improper authorization check within the queryUserAuths handler of the JeecgBoot platform. While the application enforces authentication, it fails to perform adequate server-side validation to ensure that the requestor possesses the necessary permissions to access or modify the authorization metadata of other users.\nThe root cause is a lack of object-level authorization enforcement during the execution of user information retrieval functions. Specifically, the application relies on client-supplied input for the userId parameter without verifying whether the request originates from the owner of that account or an entity authorized to audit such information.\nAttack flow begins with an authenticated attacker intercepting a legitimate request made to the queryUserAuths endpoint. Upon identifying the userId parameter, the attacker can systematically modify this value to iterate through existing system accounts. By injecting arbitrary numerical or string-based user identifiers, the attacker compels the server to return the complete JSON object associated with that user’s security context.\nThe queryUserAuths handler serves as the vulnerable component. When triggered, the backend process retrieves the associated permission set, role mappings, and assigned authorizations from the underlying database or cache layer and reflects this data back to the requester. This information disclosure provides an attacker with a comprehensive map of the system's RBAC, revealing which accounts hold administrative roles or elevated privileges.\nThe exploitation process is straightforward and does not require complex payloads or exploitation of memory corruption primitives. The attacker simply performs an HTTP GET or POST request to the target handler while manipulating the target parameter. Since the server fails to cross-reference the session user’s identity with the target userId before fetching the requested data, the operation proceeds regardless of the attacker's actual privilege level.\nPost-exploitation impact is severe, as the leaked data allows the attacker to conduct further targeted attacks. Identifying accounts with administrative roles enables the attacker to focus on secondary exploitation vectors against these high-value accounts, such as targeted phishing, session hijacking, or password spraying. Furthermore, understanding the scope of permissions can lead to the discovery of sensitive functions or hidden administrative interfaces that are restricted by the revealed permission strings, ultimately leading to a complete compromise of the system's functional integrity."
}
CVE-2026-108866: JeecgBoot Missing Authorization Vulnerability (MEDIUM Severity, CVSS: 4.3) | Sceawere