Sceawere
Vulnerability Detail
CVE-2026-108867UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
JeecgBoot Missing Authorization Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 3h ago
- Vendor
- jeecgboot
- Product
- JeecgBoot
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SystemApiController getUserRoleSetById handler that allows any authenticated user to read other users' role assignments. Low-privileged attackers can supply an arbitrary userId parameter to retrieve assigned role codes and identify administrator accounts without the system:user:queryUserRole permission.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-11T15:16:53.247Z",
"pubdate": "2026-10-11T15:16:53.247Z",
"executiveSummary": "JeecgBoot versions up to 3.9.5 are susceptible to an improper authorization vulnerability located within the SystemApiController module.\nThe vulnerability resides in the getUserRoleSetById function, which fails to enforce mandatory access control checks on user-supplied parameters.\nThis flaw allows any authenticated user, regardless of their assigned privilege level, to perform unauthorized queries against the system's role-based access control (RBAC) metadata.\nAn attacker can leverage this weakness to enumerate sensitive role assignments across the platform, facilitating the identification of administrative accounts.\nThe impact includes significant information disclosure regarding system architecture and privilege structures, which serves as a critical reconnaissance step for privilege escalation or targeted attacks.\nExploitation requires the attacker to possess a valid authentication session, although no specific elevated permissions or administrative rights are required to trigger the underlying flaw.",
"technicalDetails": "The vulnerability is classified as a missing function-level access control issue within the JeecgBoot framework, specifically impacting the SystemApiController component. The root cause is the absence of adequate authorization verification within the getUserRoleSetById handler. While the system intends to restrict access to role configuration data based on the system:user:queryUserRole permission, the implementation fails to perform this check before processing requests directed at this specific endpoint.\nThe attack flow begins when an attacker, authenticated with standard low-privileged credentials, submits a crafted HTTP request to the getUserRoleSetById interface. The endpoint expects a userId parameter to return the corresponding role codes. Due to the lack of server-side validation or authorization gating, the backend application processes the request for any valid user identifier provided by the attacker, rather than restricting the query scope to the caller's own user identity or requiring an authorized administrative context.\nBy iterating through arbitrary userId values, an attacker can conduct a systematic enumeration of the application's user database. The response from the server includes detailed role sets assigned to the target user. By observing these role sets, the attacker can pinpoint specific users possessing 'admin' or highly privileged roles. This information leakage undermines the fundamental security of the RBAC system, as it allows unauthorized parties to profile the organizational hierarchy and map out the targets of interest for subsequent exploitation phases.\nThe vulnerability persists in all versions of JeecgBoot up to and including 3.9.5. Because the vulnerability is exposed via the application's API layer, it is reachable by any client capable of interacting with the system's authenticated endpoints. The exposure is limited to authenticated users; however, the lack of sufficient authorization ensures that the principle of least privilege is not enforced for this sensitive function, allowing any authenticated session to act as a vector for reconnaissance."
}