Sceawere
Vulnerability Detail
CVE-2026-108880UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
JeecgBoot Missing Authorization Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 3h ago
- Vendor
- jeecgboot
- Product
- JeecgBoot
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the PUT /sys/dict/editDictByLowAppId endpoint that allows any authenticated user to modify low-code application dictionaries. Attackers can supply a dictionary's low_app_id, obtained from GET /sys/dict/list, via the lowAppId parameter or X-Low-App-ID header to rename dictionaries and replace their items.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-11T15:16:55.000Z",
"pubdate": "2026-10-11T15:16:55.000Z",
"executiveSummary": "JeecgBoot versions through 3.9.5 are susceptible to a missing authorization vulnerability within the application dictionary management subsystem.\nThe vulnerability resides in the PUT /sys/dict/editDictByLowAppId endpoint, which fails to enforce proper access control checks before allowing modifications.\nAn authenticated attacker can manipulate low-code application dictionaries, leading to unauthorized data modification, potential service disruption, and integrity loss of application metadata.\nThe vulnerability allows any authenticated user to exploit the lack of server-side authorization checks to rename dictionaries and replace associated items without possessing the required administrative privileges.\nThis represents a significant security oversight, as it permits lateral movement or unauthorized configuration changes within the low-code environment, undermining the platform's multi-tenant or role-based access control integrity.",
"technicalDetails": "The vulnerability is identified as a Missing Authorization flaw affecting the PUT /sys/dict/editDictByLowAppId endpoint in JeecgBoot versions up to 3.9.5.\nThe root cause is the absence of adequate authorization middleware or object-level permission validation within the controller responsible for handling dictionary edit requests.\nUnder normal operating conditions, modification of low-code application dictionaries should be restricted to users with elevated privileges or ownership rights. However, the implementation does not verify the requester's permissions against the target low_app_id.\nThe attack flow begins with the adversary enumerating existing dictionaries via the GET /sys/dict/list endpoint, which provides the necessary low_app_id identifiers for the targeted dictionary.\nOnce the target low_app_id is identified, the attacker crafts a malicious HTTP PUT request directed at /sys/dict/editDictByLowAppId. The attacker can supply the target ID either through the lowAppId parameter in the request body or via the X-Low-App-ID custom HTTP header.\nBecause the server-side logic processes these inputs without performing an access control check, the system proceeds to execute the dictionary rename operation and replaces its constituent items as dictated by the attacker's payload.\nThe scope of this vulnerability extends to all authenticated users; no elevated privileges are required to perform the exploit, as the endpoint treats any valid session token as authorized for modification actions.\nThe impact of a successful exploitation includes unauthorized modification of application configuration data, which can be leveraged to disrupt application functionality, alter user-facing dictionary content, or cause data inconsistency across the platform's low-code modules.\nThe exposure is strictly internal to the application's API surface but remains accessible to any network participant with a valid user session, including low-privileged accounts created for legitimate but restricted purposes."
}