Sceawere
Vulnerability Detail
CVE-2026-108868UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
JeecgBoot Missing Authorization Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 3h ago
- Vendor
- jeecgboot
- Product
- JeecgBoot
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to publish templated system announcements via POST /sys/api/sendBusTemplateAnnouncement. Low-privileged attackers can supply templateCode, toUser, and a forged fromUser to send notifications to arbitrary users through WebSocket, DingTalk, WeCom, Feishu and UniPush channels.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-11T15:16:53.380Z",
"pubdate": "2026-10-11T15:16:53.380Z",
"executiveSummary": "JeecgBoot versions up to 3.9.5 are susceptible to a critical missing authorization vulnerability located within the system announcement module.\nThis vulnerability allows any authenticated user to trigger the transmission of templated system announcements to arbitrary recipients.\nThe flaw stems from insufficient access control checks on the '/sys/api/sendBusTemplateAnnouncement' endpoint, which fails to validate whether the requester possesses the necessary administrative privileges to initiate system-wide notifications.\nAn attacker can exploit this to send forged notifications via WebSocket, DingTalk, WeCom, Feishu, and UniPush channels.\nBy manipulating the 'fromUser' parameter, a low-privileged attacker can impersonate system administrators or other authorized entities to deceive targets.\nThe risk implication is significant, as it facilitates social engineering attacks, phishing, and the dissemination of malicious information within an enterprise environment.\nExploitation requires a valid user session, but does not necessitate elevated permissions, making it accessible to any user registered within the JeecgBoot platform.",
"technicalDetails": "The vulnerability resides in the backend processing of the '/sys/api/sendBusTemplateAnnouncement' endpoint, which is responsible for dispatching templated announcements across multiple integrated messaging channels.\nThe root cause is a failure in the application's authorization framework to enforce role-based access control (RBAC) at the method level. While the endpoint expects a structured request body containing 'templateCode', 'toUser', and 'fromUser' parameters, the underlying controller does not verify if the authenticated user invoking the request has the authorization to perform such administrative actions.\nThe attack flow begins with the attacker establishing a valid session within the JeecgBoot instance. Once authenticated, the attacker crafts an HTTP POST request targeting the vulnerable endpoint. By providing a target 'toUser' identifier and a forged 'fromUser' identity, the attacker bypasses intended business logic restrictions.\nBecause the system trusts the input parameters without secondary verification of the 'fromUser' against the current user context, the server proceeds to process the template identified by 'templateCode'. The application then dispatches the notification through its multi-channel integration layer, which includes WebSocket, DingTalk, WeCom, Feishu, and UniPush.\nThe technical impact is twofold: First, it undermines the integrity of the internal notification system, allowing unauthorized users to broadcast messages as legitimate system administrators. Second, it exposes users of the platform to social engineering, as recipients have no technical way to distinguish between authentic system alerts and those generated by the attacker.\nThe vulnerability affects JeecgBoot versions up to 3.9.5. Successful exploitation allows for persistent or transient impersonation and potentially aids in larger, coordinated phishing campaigns within the organization's infrastructure. No specialized knowledge beyond standard API interaction is required for a successful exploit, provided the attacker has basic low-privileged access to the target instance."
}