Sceawere

Vulnerability Detail

CVE-2026-108871UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

JeecgBoot Missing Authorization in SysDepartRoleController

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
3h ago
Vendor
jeecgboot
Product
JeecgBoot
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the saveDatarule handler of SysDepartRoleController that lets low-privileged authenticated users modify department role data rules. Attackers can send crafted permissionId, roleId and dataRuleIds values to overwrite data_rule_ids, widening row-level data access or altering filtering for other department roles.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-10-11T15:16:53.777Z",
  "pubdate": "2026-10-11T15:16:53.777Z",
  "executiveSummary": "JeecgBoot versions through 3.9.5 are susceptible to a missing authorization vulnerability located within the SysDepartRoleController. This flaw resides specifically in the saveDatarule handler, which fails to implement adequate access control checks for administrative operations.\nThe vulnerability allows a low-privileged authenticated user to manipulate department role data rules, effectively bypassing intended security constraints. By submitting crafted requests, an attacker can modify the association between roles and data filtering rules. This represents a significant security risk, as it enables unauthorized modification of sensitive access control logic.\nThe exploitation of this vulnerability requires the attacker to be authenticated within the application. Once authenticated, the attacker can leverage the lack of authorization checks to overwrite the data_rule_ids for arbitrary roles, leading to privilege escalation or unauthorized data exposure through manipulated row-level security policies.\nThe impact includes the potential for horizontal or vertical privilege escalation and the compromise of data integrity and confidentiality across the application's multi-tenant or departmental structure. There is no requirement for high-level administrative privileges, making the threshold for exploitation relatively low for an already authenticated user.",
  "technicalDetails": "The root cause of this vulnerability is a missing authorization check within the saveDatarule method of the SysDepartRoleController component in JeecgBoot. The application fails to verify whether the currently authenticated user possesses the appropriate permissions to modify the data rule configurations associated with specific department roles.\nThe vulnerable handler is designed to manage the mapping of data rules to department roles. Under normal operating conditions, this function should be restricted to administrators or users with specific management privileges. However, the implementation lacks the necessary server-side security checks, allowing any authenticated user to invoke the endpoint.\nThe attack flow proceeds as follows: An attacker with low-level authenticated access identifies the SysDepartRoleController endpoint responsible for saving data rules. The attacker crafts an HTTP request containing specific parameters, including permissionId, roleId, and an array or list of dataRuleIds. Upon receiving this request, the application processes the input without verifying the requester's authority over the target roleId.\nBy manipulating the dataRuleIds parameter, the attacker can overwrite the existing configuration in the underlying database for the specified roleId. This effectively alters the row-level data access filtering mechanism for the target role. Because the application relies on these rule identifiers to enforce data segmentation, an attacker can widen or restrict access rules, potentially granting themselves or others access to records that should remain inaccessible.\nThe scope of this vulnerability is global across all JeecgBoot instances up to and including version 3.9.5. Because the application logic for data access control is server-side and depends on the integrity of the configuration managed by this controller, the impact is consistent regardless of the underlying database configuration. The failure to validate the caller's identity against the target's scope effectively disables the intended multi-departmental security isolation provided by the framework.\nPost-exploitation, the attacker maintains control over the manipulated data rules until an administrator identifies the unauthorized change and reverts the settings. During the period of compromise, the attacker can effectively manipulate the application's view of data, potentially leading to unauthorized data exfiltration or the bypassing of business logic that relies on these row-level security constraints."
}
CVE-2026-108871: JeecgBoot Missing Authorization in SysDepartRoleController (MEDIUM Severity, CVSS: 5.4) | Sceawere