Sceawere

Vulnerability Detail

CVE-2026-108882UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

JeecgBoot Missing Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
3h ago
Vendor
jeecgboot
Product
JeecgBoot
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysPositionController removeUserPosition handler that allows any authenticated user to remove position members. Low-privileged attackers can send DELETE requests with arbitrary userIds and positionId values to delete sys_user_position rows, detaching users from positions without logging.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-10-11T15:16:55.263Z",
  "pubdate": "2026-10-11T15:16:55.263Z",
  "executiveSummary": "JeecgBoot versions through 3.9.5 are susceptible to a missing authorization vulnerability located within the SysPositionController component. The flaw arises from an improper access control implementation in the removeUserPosition handler, which fails to validate the requester's authorization level before executing administrative operations.\nThe vulnerability allows any authenticated user to perform unauthorized deletions of user-position associations within the system's database. By manipulating the parameters of a DELETE request, an attacker can detach arbitrary users from specific positions without triggering system audit logs.\nThis represents a significant integrity and availability risk, as unauthorized actors can disrupt administrative hierarchies, revoke user access to specific functional roles, and manipulate organizational structures. Exploitation does not require elevated privileges, as any account with valid session authentication can interact with the vulnerable endpoint. The impact is primarily focused on unauthorized data modification and potential operational disruption, with no evidence of remote code execution. Immediate remediation is required to ensure that proper role-based access control (RBAC) checks are enforced on all handler methods.",
  "technicalDetails": "The vulnerability is situated in the SysPositionController class of the JeecgBoot framework. The specific handler identified is removeUserPosition, which is responsible for managing the sys_user_position table. The root cause is a failure to enforce authorization checks during the processing of DELETE requests sent to this specific route.\nUnder normal operating conditions, the application should verify that the authenticated user possesses the necessary administrative permissions or authorization tokens to modify position assignments. However, the current implementation lacks an intercepter or programmatic check to validate the user's role before processing the request.\nAn attacker can exploit this by crafting a malicious HTTP DELETE request targeting the vulnerable endpoint. The request body or URL parameters include arbitrary 'userId' and 'positionId' values. Because the backend does not validate the relationship between the requester and the target resources, the application proceeds to execute a database deletion command against the sys_user_position table.\nThe attack flow follows these steps: 1. The attacker authenticates as a standard, low-privileged user to obtain a valid session token. 2. The attacker identifies the API endpoint associated with the removeUserPosition handler. 3. The attacker constructs a HTTP DELETE request, injecting target 'userId's and 'positionId's that they are not authorized to modify. 4. The application processes the request, bypassing authentication checks, and executes the SQL query to remove the specified row in the sys_user_position database table. 5. The association between the target user and the specified position is permanently deleted.\nThis flaw leads to a state of unauthorized data mutation. Because the action occurs silently, the lack of logging mechanism further complicates incident response and forensic analysis. This vulnerability is present in all versions of JeecgBoot up to and including 3.9.5. The scope of exploitation is limited to the local database integrity regarding position mappings; however, the ability to arbitrarily remove users from positions can be leveraged to bypass internal logic, disrupt workflows, or facilitate social engineering attacks by removing legitimate authorized users from key positions."
}
CVE-2026-108882: JeecgBoot Missing Authorization Vulnerability (MEDIUM Severity, CVSS: 5.4) | Sceawere