Sceawere
Vulnerability Detail
CVE-2026-108887UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
JeecgBoot Missing Authorization in ExportXls
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 3h ago
- Vendor
- jeecgboot
- Product
- JeecgBoot
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysCommentController exportXls handler that allows any authenticated user to export all comments. Low-privileged attackers can request /sys/comment/exportXls to download every sys_comment row, including comment text and user ids on records they cannot access.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-11T15:16:55.930Z",
"pubdate": "2026-10-11T15:16:55.930Z",
"executiveSummary": "JeecgBoot versions through 3.9.5 are susceptible to a missing authorization vulnerability located within the SysCommentController component. The flaw resides specifically in the exportXls handler, which fails to implement adequate access control checks for exported data. This vulnerability allows any authenticated user, regardless of their privilege level or data access permissions, to trigger a bulk export of the entire sys_comment database table. The impact is significant, as it facilitates the unauthorized disclosure of sensitive information, including private comment content and associated user identifiers. The attack requires authenticated access to the application, but it does not necessitate elevated administrative privileges, making it a serious risk for data confidentiality. An attacker can leverage this endpoint to perform mass data exfiltration of internal communications, potentially compromising user privacy and revealing internal system activity logs stored within the comment module.",
"technicalDetails": "The root cause of this vulnerability is a missing authorization check within the SysCommentController class of the JeecgBoot framework, specifically targeting the exportXls method. In standard secure implementations, an export handler should validate the requesting user's session permissions against the scope of the requested data. In this instance, the controller fails to verify if the authenticated user has the necessary authorization to perform an export operation, nor does it filter the query results based on the user's data visibility scopes.\nThe vulnerability is exposed via the /sys/comment/exportXls endpoint. When an authenticated user submits an HTTP request to this path, the application triggers the backend logic responsible for serializing the sys_comment table records into an Excel format for download. Because the underlying controller lacks a security interceptor or internal permission check, the query executes with the database context's full permission level, effectively ignoring row-level security or role-based access control (RBAC) constraints.\nThe attack flow proceeds as follows: First, an attacker authenticates to the JeecgBoot platform using a valid, low-privileged user account. Once authenticated, the attacker constructs an HTTP GET request directed at /sys/comment/exportXls. The server, processing the request through the SysCommentController, initiates the data retrieval process from the sys_comment table without applying any authorization filters. The resulting dataset, containing all records including comments and user IDs that the low-privileged attacker should not have visibility into, is then packaged into an export file. Finally, the server returns this file to the attacker, resulting in a successful unauthorized data exfiltration.\nAffected versions include all releases of JeecgBoot up to and including 3.9.5. The vulnerability is categorized as an Insecure Direct Object Reference (IDOR) variant or a Broken Function Level Authorization (BFLA) flaw. The exploitation does not require advanced technical skill, as the attacker merely needs to invoke a standard functional endpoint. The post-exploitation impact includes the loss of confidentiality regarding user interaction data, which may be exploited for reconnaissance, tracking user activity, or social engineering purposes within the environment."
}