Sceawere

Vulnerability Detail

CVE-2026-108886UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

JeecgBoot Missing Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
jeecgboot
Product
JeecgBoot
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysUserController queryChildrenByUsername handler that allows any authenticated user to retrieve other users' account records. Low-privileged attackers can supply arbitrary userId values to obtain names, emails, phone numbers, employee numbers, department assignments, and staff lists of departments those users head.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-11T15:16:55.800Z",
  "pubdate": "2026-10-11T15:16:55.800Z",
  "executiveSummary": "JeecgBoot versions through 3.9.5 are susceptible to a missing authorization vulnerability located within the SysUserController component.\nThis flaw resides in the queryChildrenByUsername handler, which fails to implement adequate access control checks for requested resource identifiers.\nThe vulnerability allows any authenticated user to perform unauthorized enumeration of account records by supplying arbitrary userId values.\nImpact includes the unauthorized disclosure of sensitive personally identifiable information (PII), such as full names, email addresses, phone numbers, employee identification numbers, and organizational hierarchy data.\nThe attack requires a valid, low-privileged authentication session; however, it does not require administrative rights or specific high-level permissions to execute.\nThe risk implication is significant as it facilitates mass data harvesting of the user database, potentially leading to social engineering, targeted phishing, or reconnaissance for further system compromise.\nThe vulnerability is inherent to the application logic, necessitating a structural update to the backend authorization framework to ensure that users can only access records relevant to their own authorized scope.",
  "technicalDetails": "The vulnerability is classified as an Insecure Direct Object Reference (IDOR) or a Missing Authorization flaw resulting from insufficient server-side validation of user-supplied input.\nThe vulnerable component is identified as SysUserController, specifically within the logic governing the queryChildrenByUsername function.\nIn the affected versions (through 3.9.5), the application backend fails to verify whether the authenticated user possesses the appropriate permissions to view the account details associated with a provided userId parameter.\nThe exploitation flow begins when an authenticated attacker intercepts or crafts a request targeting the queryChildrenByUsername endpoint. By iterating through or arbitrarily modifying the userId parameters within the request body or query string, the attacker bypasses standard access control mechanisms.\nBecause the server-side code does not perform an ownership check or a role-based authorization validation, the application processes the request as a legitimate query. The backend retrieves the requested database records and returns them in the response, typically in a serialized JSON format.\nData retrieved through this mechanism includes sensitive attributes such as: internal employee numbers, organizational department assignments, and specific metadata regarding department leadership. This exposure extends the impact beyond simple account identification, providing an attacker with a comprehensive map of the internal organizational structure.\nThe lack of integrity and confidentiality checks at the controller level means that the system treats the input userId as trusted data rather than untrusted user input. This architectural oversight allows the attacker to systematically scrape the entire user directory.\nThis vulnerability is particularly dangerous in environments where the user directory is large, as automated scripts can easily enumerate every user in the system within a minimal timeframe, resulting in a full breach of sensitive PII.\nThe failure occurs because the authorization logic is decoupled from the data retrieval process, allowing the service layer to fulfill requests even when the requesting subject is not authorized to view the target object. Remediation requires an enforcement point that maps the authenticated principal's context against the requested resource ID before execution of the database query."
}
CVE-2026-108886: JeecgBoot Missing Authorization Vulnerability (MEDIUM Severity, CVSS: 4.3) | Sceawere