Sceawere
Vulnerability Detail
CVE-2026-108870UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
JeecgBoot Missing Authorization in SysRoleController
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 3h ago
- Vendor
- jeecgboot
- Product
- JeecgBoot
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysRoleController saveDatarule handler that allows low-privileged authenticated users to modify role data rules. Attackers can send permissionId, roleId and dataRuleIds to overwrite data_rule_ids, clearing row-level filters to widen readable records or altering filtering for other roles.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-10-11T15:16:53.643Z",
"pubdate": "2026-10-11T15:16:53.643Z",
"executiveSummary": "JeecgBoot versions up to and including 3.9.5 are susceptible to a critical missing authorization vulnerability located within the SysRoleController component.\nThe vulnerability resides specifically in the saveDatarule handler, which fails to implement adequate access control checks for incoming requests.\nThis security flaw allows a low-privileged authenticated user to manipulate system-wide role-based data filtering configurations.\nBy bypassing authorization constraints, an attacker can modify data_rule_ids for arbitrary roles, effectively overriding defined row-level security policies.\nThe primary risk implications include unauthorized data exposure through the removal of record filters and the potential to disrupt organizational access control models by altering permission scopes.\nSuccessful exploitation requires the attacker to possess authenticated access to the application, although no elevated administrative privileges are necessary to execute the request.\nThe impact is significant, as it facilitates unauthorized access to sensitive records that were previously restricted by dynamic data rules.",
"technicalDetails": "The vulnerability is a classic case of Broken Access Control (BAC) where the application logic fails to verify if the authenticated requester possesses the administrative privileges required to modify role-based data rules.\nThe root cause is identified in the SysRoleController.saveDatarule() function, which processes requests to update data rule mappings for roles without enforcing a robust server-side authorization check.\nAn attacker can exploit this by crafting a POST request directed at the saveDatarule endpoint. The request body must include specific parameters, namely 'permissionId', 'roleId', and 'dataRuleIds'.\nUpon receiving the request, the application blindly processes the supplied parameters to perform a database update operation. Specifically, the system overwrites the 'data_rule_ids' associated with the specified 'roleId' in the backend persistence layer.\nThe attack flow follows these steps: 1) The attacker authenticates as a standard, low-privileged user. 2) The attacker intercepts or reconstructs a request targeting the saveDatarule handler. 3) The attacker injects malicious values into the 'dataRuleIds' parameter corresponding to a target 'roleId'. 4) The controller executes the persistence logic, effectively modifying the data filtering scope for the targeted role.\nBecause the server lacks a validation check to ensure the requester is an authorized administrator, the database records are updated as requested by the low-privileged session.\nThe post-exploitation impact allows for severe data leakage. By clearing or modifying the 'data_rule_ids', the attacker can disable row-level security (RLS) filters. This effectively widens the scope of data visibility for the targeted role, allowing users assigned to that role to view records that were meant to be restricted, such as sensitive PII or financial entries.\nThe vulnerability persists across all versions of JeecgBoot up to 3.9.5. Given the architectural nature of the flaw in the Controller layer, network exposure is inherent for any deployment where the management API is accessible, regardless of whether the specific role management UI is exposed to standard users."
}