Sceawere
Vulnerability Detail
CVE-2026-108885UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
JeecgBoot Missing Authorization in SysMessageController
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 3h ago
- Vendor
- jeecgboot
- Product
- JeecgBoot
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysMessageController delete handler that allows low-privileged authenticated users to delete message records. Attackers can send DELETE requests with arbitrary id values to remove any sys_sms row, erasing records of sent notifications without ownership checks.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-10-11T15:16:55.670Z",
"pubdate": "2026-10-11T15:16:55.670Z",
"executiveSummary": "JeecgBoot versions through 3.9.5 are susceptible to a missing authorization vulnerability within the SysMessageController component. This flaw resides in the delete handler functionality, which fails to perform adequate server-side ownership verification before executing record deletion operations.\nThe vulnerability allows a low-privileged, authenticated user to perform unauthorized deletions of message records stored in the sys_sms database table. By crafting and sending a specific DELETE request targeting arbitrary identifier (id) values, an attacker can purge historical notification logs without the requisite administrative or ownership privileges.\nThe risk implication is significant as it facilitates the unauthorized removal of communication records, which may have legal, forensic, or audit implications. The exploit requires an existing low-privileged account on the target system to authenticate, after which the attacker can bypass logical access controls to manipulate data. No complex preconditions beyond authentication are required to trigger the vulnerable code path.",
"technicalDetails": "The root cause of this vulnerability is an Insecure Direct Object Reference (IDOR) pattern stemming from missing authorization checks in the SysMessageController. While the application requires authentication to reach the controller endpoint, the server-side logic fails to validate the requester's identity against the object owner or administrative permissions before performing the database deletion operation.\nThe vulnerable component is identified as the delete handler method within the SysMessageController class. Upon receiving a request to delete a specific message record, the application retrieves the target row from the sys_sms database table based on the provided identifier parameter. Because the controller does not verify whether the authenticated user has sufficient authorization to delete the specific message entry, the system proceeds to execute the deletion command against the database using the provided id.\nThe exploitation flow proceeds as follows: First, an attacker logs into the JeecgBoot platform using a standard, low-privileged user account. Second, the attacker identifies the API endpoint associated with the message deletion function within the SysMessageController. Third, the attacker captures or constructs a DELETE request targeting the system's message management interface, injecting target identifier values into the request body or URL parameters. Finally, the server receives the malicious request and, lacking a gatekeeper check for object ownership or permission levels, executes the SQL DELETE command on the sys_sms table for the specified ID.\nThis vulnerability exposes the integrity of notification records stored in sys_sms. The impact of successful exploitation is the unauthorized erasure of sent notifications. This could be used maliciously to cover tracks of system activity or to disrupt communication history logs within the application. The vulnerability affects all versions of JeecgBoot up to and including 3.9.5, representing a failure in the application's access control architecture regarding CRUD operations on sensitive data entities."
}