Sceawere

Vulnerability Detail

CVE-2026-108875UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

JeecgBoot Missing Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
jeecgboot
Product
JeecgBoot
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysUserController addSysUserGroup handler that allows any authenticated user to modify user group membership. Low-privileged attackers can send POST requests with arbitrary user ids and a groupId to add any users to administrator-maintained groups without permission checks.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-11T15:16:54.330Z",
  "pubdate": "2026-10-11T15:16:54.330Z",
  "executiveSummary": "JeecgBoot versions up to and including 3.9.5 are susceptible to a critical missing authorization vulnerability within the SysUserController component.\nThe flaw resides in the addSysUserGroup handler, which fails to enforce access control checks when assigning users to specific groups.\nAn authenticated attacker, regardless of their original privilege level, can exploit this oversight to manipulate user group memberships.\nThis vulnerability poses a significant risk to the integrity of the authorization model, as it allows for unauthorized privilege escalation.\nBy adding arbitrary user identifiers to administrative-level groups, an attacker can gain unauthorized access to sensitive system resources or administrative functions.\nExploitation requires only a valid, low-privileged user account and the ability to submit crafted POST requests to the vulnerable API endpoint.\nThe primary risk implication is the potential for full system compromise through the elevation of attacker-controlled accounts to administrative status.",
  "technicalDetails": "The vulnerability is rooted in an improper authorization check within the addSysUserGroup handler located in the SysUserController class of the JeecgBoot framework.\nThe application processes requests to modify user group associations without validating that the authenticated user initiating the request possesses the necessary administrative privileges to perform such modifications.\nThe vulnerable function accepts parameters, specifically user identifiers and group identifiers, and processes them to perform database updates on group membership tables.\nBecause the server-side code does not perform a permission check against the caller's session context or role-based access control (RBAC) policies, any user with a valid authentication token can invoke this functionality.\nThe attack flow proceeds as follows: First, the attacker authenticates to the JeecgBoot platform using a low-privileged account. Second, the attacker identifies the target user ID and the ID of an administrative or high-privileged group that they wish to join. Third, the attacker crafts a POST request targeting the /sys/user/addSysUserGroup endpoint (or equivalent mapped route), supplying the identified user and group IDs in the request body.\nUpon receipt, the server executes the business logic to bind the specified user to the group. Since the validation layer is absent, the backend completes the transaction, effectively granting the target user the privileges associated with that group.\nThis missing authorization flaw bypasses security constraints intended to restrict sensitive membership changes to system administrators only.\nThe technical impact includes privilege escalation and the potential for lateral movement within the application, as the attacker can elevate their own account or manipulate the roles of other users to gain illicit administrative control.\nThis issue affects all JeecgBoot installations running version 3.9.5 or earlier. The exploitation does not require advanced technical skill, as it relies on the systematic omission of security controls in the function handling group assignments.\nPost-exploitation, an attacker can perform actions restricted to members of the targeted group, leading to a complete compromise of the system's security posture and potentially enabling data exfiltration, system configuration changes, or the execution of administrative commands."
}
CVE-2026-108875: JeecgBoot Missing Authorization Vulnerability (MEDIUM Severity, CVSS: 4.3) | Sceawere