Sceawere

Vulnerability Detail

CVE-2026-108883UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

JeecgBoot Missing Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
jeecgboot
Product
JeecgBoot
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the editThirdAppConfig handler that allows any authenticated user to modify third-party application configurations. Low-privileged attackers can replace client id, client secret, agent id and corp id of DingTalk, WeCom or Feishu integrations to redirect directory synchronisation and messaging to attacker-controlled applications or break them.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-11T15:16:55.400Z",
  "pubdate": "2026-10-11T15:16:55.400Z",
  "executiveSummary": "JeecgBoot versions up to 3.9.5 are susceptible to a missing authorization vulnerability located within the editThirdAppConfig handler.\nThe vulnerability allows any authenticated user, regardless of their privilege level, to modify sensitive third-party application configurations.\nBy manipulating these configurations—specifically parameters related to DingTalk, WeCom, and Feishu—attackers can facilitate unauthorized redirection of directory synchronization processes and messaging traffic.\nThis flaw presents significant security implications, as it enables the redirection of administrative communication channels to attacker-controlled infrastructure.\nExploitation requires that the attacker has authenticated access to the platform; however, no administrative privileges are required to execute the configuration override.\nSuccessful exploitation compromises the integrity of identity management and external service integration, potentially leading to information disclosure or full service disruption of third-party integrations.",
  "technicalDetails": "The vulnerability originates from an improper access control mechanism within the application's backend logic, specifically involving the editThirdAppConfig handler function.\nThe root cause is a failure to implement server-side authorization checks on the administrative endpoint, which allows any authenticated user to transmit requests that modify the system's global integration settings.\nThe affected component manages third-party authentication and notification integrations, including credentials and identifiers for DingTalk, WeCom, and Feishu.\nSpecifically, the handler accepts updates for critical parameters such as client_id, client_secret, agent_id, and corp_id. Due to the lack of role-based access control (RBAC) validation, the application processes these requests without verifying the user's authorization to perform administrative configuration tasks.\nThe attack flow proceeds as follows: First, an attacker authenticates to the JeecgBoot platform using low-privileged credentials. Second, the attacker interacts with the editThirdAppConfig handler by crafting a malicious HTTP request containing modified third-party integration parameters. Third, the backend, lacking adequate authorization checks, accepts the request and overwrites the existing configuration in the underlying database.\nUpon successful modification, the attacker can redirect directory synchronization data to an external, attacker-controlled server. This effectively enables the interception of sensitive synchronization traffic or the injection of malicious payloads into the system's messaging pipeline.\nThe post-exploitation impact includes the total subversion of third-party platform integrations, potential account takeover via malicious synchronization, and the disruption of legitimate enterprise communication flows. Because this is a missing authorization flaw rather than a parameter validation issue, the system correctly updates the configuration with the malicious values, making the modification persist until manually reverted by an administrator."
}
CVE-2026-108883: JeecgBoot Missing Authorization Vulnerability (MEDIUM Severity, CVSS: 6.5) | Sceawere