Sceawere

Vulnerability Detail

CVE-2026-108874UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

JeecgBoot Missing Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
jeecgboot
Product
JeecgBoot
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to assign or remove department heads by calling PUT /sys/user/changeDepartChargePerson. Low-privileged attackers can supply arbitrary userId, department id, and status values to make any user a department head, widening department-scoped views, or demote existing heads.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-11T15:16:54.193Z",
  "pubdate": "2026-10-11T15:16:54.193Z",
  "executiveSummary": "JeecgBoot versions through 3.9.5 are susceptible to a critical missing authorization vulnerability located within the system's user management module.\nThe vulnerability allows an authenticated attacker, regardless of their original privilege level, to manipulate the authorization status of department heads.\nBy invoking the PUT /sys/user/changeDepartChargePerson endpoint, an attacker can arbitrarily promote any system user to a department head or demote existing legitimate department heads.\nThis flaw facilitates unauthorized privilege escalation within the organizational hierarchy, potentially granting low-privileged users access to sensitive, department-scoped administrative functions and data views that should be restricted.\nThe vulnerability requires an active, authenticated session, but bypasses all internal Role-Based Access Control (RBAC) checks typically enforced for administrative personnel management actions.\nThe risk implication is significant as it undermines the integrity of the system's user management and organizational access control model.",
  "technicalDetails": "The root cause of this vulnerability is the absence of sufficient server-side access control checks within the /sys/user/changeDepartChargePerson API endpoint. While the endpoint is protected by general session authentication, the backend logic fails to validate whether the authenticated user possesses the 'Administrator' or 'HR Manager' privileges required to perform administrative modifications to organizational roles.\nThe vulnerable component resides in the system's user management controller, which processes requests to update department-specific administrative flags. The application accepts a JSON payload containing the 'userId', 'depId', and 'status' parameters without verifying the authority of the requesting user to mutate these specific fields.\nThe exploitation flow begins when an attacker, possessing a valid but low-privileged session token, crafts a PUT request to /sys/user/changeDepartChargePerson. The attacker populates the request body with the target 'userId' (the user they wish to promote) and the corresponding 'depId'. By setting the 'status' parameter to the appropriate value, the attacker forces the system to update the user's role assignment in the database.\nBecause the system trusts the input parameters implicitly, the backend process updates the user's status within the underlying data store. This action immediately grants the target user the elevated permissions associated with a department head. From a post-exploitation perspective, the attacker can leverage these newly acquired permissions to access department-scoped views, modify other user records, or influence workflows that are restricted to department-level leadership.\nThe vulnerability affects JeecgBoot versions 3.9.5 and below. The exposure is limited to authenticated users; however, since even accounts with minimal privileges can trigger this logic, the attack surface effectively includes all registered system participants. There is no requirement for elevated internal privileges to bypass the security check, making this a classic broken access control flaw (often categorized under insecure direct object reference or missing function-level access control). The lack of input validation regarding the requester's identity or functional capability allows for complete circumvention of the intended administrative workflow."
}
CVE-2026-108874: JeecgBoot Missing Authorization Vulnerability (MEDIUM Severity, CVSS: 4.3) | Sceawere