Sceawere

Vulnerability Detail

CVE-2026-108872UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

JeecgBoot Missing Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
jeecgboot
Product
JeecgBoot
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the batchEditUsers handler of SysUserController that allows any authenticated user to edit user department assignments. Low-privileged attackers can send PUT requests to /sys/user/batchEditUsers with arbitrary user and department ids to move users, including administrators, between departments and overwrite positions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-11T15:16:53.910Z",
  "pubdate": "2026-10-11T15:16:53.910Z",
  "executiveSummary": "JeecgBoot versions through 3.9.5 are susceptible to a missing authorization vulnerability located within the SysUserController.\nThe vulnerability allows an authenticated user to perform unauthorized modifications to user department assignments by interacting with the batchEditUsers handler.\nThis flaw enables low-privileged attackers to manipulate organizational structures, effectively moving arbitrary users—including high-privileged administrators—to different departments or overwriting their defined positions.\nThe impact of this unauthorized access includes potential privilege escalation, disruption of internal workflows, and the circumvention of administrative access controls tied to departmental permissions.\nExploitation requires the attacker to possess a valid authenticated session, although the system fails to enforce proper server-side authorization checks for the requested operation.\nThe risk is categorized as critical within an enterprise context due to the potential for administrative account manipulation and the systemic integrity of the user management framework.",
  "technicalDetails": "The vulnerability exists in the batchEditUsers handler of the SysUserController component in JeecgBoot, which fails to implement granular access control checks.\nRoot cause analysis indicates an Improper Authorization vulnerability (CWE-285) where the application logic assumes that the invocation of the batch update function is inherently authorized if a user session is active.\nThe endpoint /sys/user/batchEditUsers accepts PUT requests that contain user identifiers and target department mapping configurations. Because the application logic lacks a validation layer to verify whether the requesting user possesses administrative authority to modify specific target accounts or departmental associations, it processes the request as legitimate.\nThe attack flow follows a predictable pattern: 1) The attacker authenticates to the application using a standard, low-privileged user account. 2) The attacker crafts a malicious PUT request directed at the /sys/user/batchEditUsers endpoint, including a JSON payload that specifies the IDs of targeted users and the desired destination department IDs. 3) The server-side controller receives the request and executes the update operation directly against the underlying database without cross-referencing the attacker's permissions against the target user's metadata.\nBy manipulating these fields, an attacker can move administrators out of restricted departments or inject themselves into sensitive organizational units that may have inherited permissions or higher access tiers. The ability to overwrite positions further allows an attacker to compromise the integrity of internal role-based access control (RBAC) models by reassigning job functions to malicious or unauthorized actors.\nSince the vulnerability is exposed via standard HTTP methods, it is readily accessible to any authenticated user within the network, requiring no complex interaction beyond the ability to intercept or construct standard API calls. Post-exploitation impact is severe, as the attacker effectively gains control over the organizational hierarchy and can leverage the reassignment of administrative accounts to facilitate further lateral movement or privilege escalation across the JeecgBoot platform."
}
CVE-2026-108872: JeecgBoot Missing Authorization Vulnerability (MEDIUM Severity, CVSS: 4.3) | Sceawere