Sceawere

Vulnerability Detail

CVE-2026-108884UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

JeecgBoot Missing Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
3h ago
Vendor
jeecgboot
Product
JeecgBoot
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysMessageTemplateController delete handler that allows any authenticated user to delete message templates. Low-privileged attackers can obtain template ids from the unguarded list endpoint and delete shipped notification templates, causing system notices and workflow reminders to fail.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-10-11T15:16:55.533Z",
  "pubdate": "2026-10-11T15:16:55.533Z",
  "executiveSummary": "JeecgBoot versions up to 3.9.5 are susceptible to an improper authorization vulnerability located within the SysMessageTemplateController delete handler.\nThe flaw allows any authenticated user to perform unauthorized deletion of system message templates, representing an Improper Access Control issue.\nSuccessful exploitation results in the permanent removal of critical notification and workflow templates, leading to denial-of-service for automated system communications.\nThe vulnerability requires the attacker to possess an authenticated session, though it does not necessitate administrative privileges.\nRisk implications include significant disruption to organizational workflows, failure of automated system notices, and potential degradation of platform reliability.\nThere are no complex exploitation requirements; the attacker only needs to discover valid template identifiers, which are exposed via an insufficiently protected API endpoint, and issue a deletion request to the vulnerable controller.",
  "technicalDetails": "The vulnerability resides within the SysMessageTemplateController component of the JeecgBoot framework. The root cause is a failure to implement appropriate server-side access control checks (authorization checks) on the delete method responsible for removing message templates.\nIn JeecgBoot versions through 3.9.5, the application relies on inadequate security constraints for the delete functionality, failing to verify whether the authenticated user possesses the 'admin' or appropriate 'system configuration' roles before executing the removal process.\nThe attack flow begins with an authenticated user accessing the list endpoint for message templates. Because this endpoint lacks proper authorization constraints, it enumerates and returns a collection of template IDs to the requester. An attacker can harvest these IDs systematically.\nUpon obtaining valid target identifiers, the attacker can then invoke the delete handler within SysMessageTemplateController. By sending a crafted HTTP request (typically a DELETE request) targeting specific template IDs, the attacker triggers the application logic to remove the records from the database without verifying the authorization context of the request initiator.\nBecause the system trusts the incoming request without validating the user's privilege level, the database operation proceeds, resulting in the successful deletion of notification and workflow templates. This leads to an immediate impact on system availability, as processes relying on these templates fail to execute properly.\nThe vulnerability is accessible to any user with a valid authenticated session, regardless of their role within the application. No specialized bypass techniques are required, as the function simply lacks the security annotations or interceptors necessary to prevent unauthorized requests from being processed.\nThe post-exploitation impact includes a loss of service availability regarding automated system notices and workflow management. Since these templates are essential for the operation of critical platform alerts, the removal of these templates effectively disables key business logic workflows, forcing administrators to manually restore the template data from backups."
}
CVE-2026-108884: JeecgBoot Missing Authorization Vulnerability (MEDIUM Severity, CVSS: 5.4) | Sceawere