Sceawere
Vulnerability Detail
CVE-2026-108884UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
JeecgBoot Missing Authorization Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 3h ago
- Vendor
- jeecgboot
- Product
- JeecgBoot
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysMessageTemplateController delete handler that allows any authenticated user to delete message templates. Low-privileged attackers can obtain template ids from the unguarded list endpoint and delete shipped notification templates, causing system notices and workflow reminders to fail.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-10-11T15:16:55.533Z",
"pubdate": "2026-10-11T15:16:55.533Z",
"executiveSummary": "JeecgBoot versions up to 3.9.5 are susceptible to an improper authorization vulnerability located within the SysMessageTemplateController delete handler.\nThe flaw allows any authenticated user to perform unauthorized deletion of system message templates, representing an Improper Access Control issue.\nSuccessful exploitation results in the permanent removal of critical notification and workflow templates, leading to denial-of-service for automated system communications.\nThe vulnerability requires the attacker to possess an authenticated session, though it does not necessitate administrative privileges.\nRisk implications include significant disruption to organizational workflows, failure of automated system notices, and potential degradation of platform reliability.\nThere are no complex exploitation requirements; the attacker only needs to discover valid template identifiers, which are exposed via an insufficiently protected API endpoint, and issue a deletion request to the vulnerable controller.",
"technicalDetails": "The vulnerability resides within the SysMessageTemplateController component of the JeecgBoot framework. The root cause is a failure to implement appropriate server-side access control checks (authorization checks) on the delete method responsible for removing message templates.\nIn JeecgBoot versions through 3.9.5, the application relies on inadequate security constraints for the delete functionality, failing to verify whether the authenticated user possesses the 'admin' or appropriate 'system configuration' roles before executing the removal process.\nThe attack flow begins with an authenticated user accessing the list endpoint for message templates. Because this endpoint lacks proper authorization constraints, it enumerates and returns a collection of template IDs to the requester. An attacker can harvest these IDs systematically.\nUpon obtaining valid target identifiers, the attacker can then invoke the delete handler within SysMessageTemplateController. By sending a crafted HTTP request (typically a DELETE request) targeting specific template IDs, the attacker triggers the application logic to remove the records from the database without verifying the authorization context of the request initiator.\nBecause the system trusts the incoming request without validating the user's privilege level, the database operation proceeds, resulting in the successful deletion of notification and workflow templates. This leads to an immediate impact on system availability, as processes relying on these templates fail to execute properly.\nThe vulnerability is accessible to any user with a valid authenticated session, regardless of their role within the application. No specialized bypass techniques are required, as the function simply lacks the security annotations or interceptors necessary to prevent unauthorized requests from being processed.\nThe post-exploitation impact includes a loss of service availability regarding automated system notices and workflow management. Since these templates are essential for the operation of critical platform alerts, the removal of these templates effectively disables key business logic workflows, forcing administrators to manually restore the template data from backups."
}