Sceawere

Vulnerability Detail

CVE-2026-108887UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

JeecgBoot Missing Authorization in ExportXls

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
jeecgboot
Product
JeecgBoot
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysCommentController exportXls handler that allows any authenticated user to export all comments. Low-privileged attackers can request /sys/comment/exportXls to download every sys_comment row, including comment text and user ids on records they cannot access.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-11T15:16:55.930Z",
  "pubdate": "2026-10-11T15:16:55.930Z",
  "executiveSummary": "JeecgBoot versions through 3.9.5 are susceptible to a missing authorization vulnerability located within the SysCommentController component. The flaw resides specifically in the exportXls handler, which fails to implement adequate access control checks for exported data. This vulnerability allows any authenticated user, regardless of their privilege level or data access permissions, to trigger a bulk export of the entire sys_comment database table. The impact is significant, as it facilitates the unauthorized disclosure of sensitive information, including private comment content and associated user identifiers. The attack requires authenticated access to the application, but it does not necessitate elevated administrative privileges, making it a serious risk for data confidentiality. An attacker can leverage this endpoint to perform mass data exfiltration of internal communications, potentially compromising user privacy and revealing internal system activity logs stored within the comment module.",
  "technicalDetails": "The root cause of this vulnerability is a missing authorization check within the SysCommentController class of the JeecgBoot framework, specifically targeting the exportXls method. In standard secure implementations, an export handler should validate the requesting user's session permissions against the scope of the requested data. In this instance, the controller fails to verify if the authenticated user has the necessary authorization to perform an export operation, nor does it filter the query results based on the user's data visibility scopes.\nThe vulnerability is exposed via the /sys/comment/exportXls endpoint. When an authenticated user submits an HTTP request to this path, the application triggers the backend logic responsible for serializing the sys_comment table records into an Excel format for download. Because the underlying controller lacks a security interceptor or internal permission check, the query executes with the database context's full permission level, effectively ignoring row-level security or role-based access control (RBAC) constraints.\nThe attack flow proceeds as follows: First, an attacker authenticates to the JeecgBoot platform using a valid, low-privileged user account. Once authenticated, the attacker constructs an HTTP GET request directed at /sys/comment/exportXls. The server, processing the request through the SysCommentController, initiates the data retrieval process from the sys_comment table without applying any authorization filters. The resulting dataset, containing all records including comments and user IDs that the low-privileged attacker should not have visibility into, is then packaged into an export file. Finally, the server returns this file to the attacker, resulting in a successful unauthorized data exfiltration.\nAffected versions include all releases of JeecgBoot up to and including 3.9.5. The vulnerability is categorized as an Insecure Direct Object Reference (IDOR) variant or a Broken Function Level Authorization (BFLA) flaw. The exploitation does not require advanced technical skill, as the attacker merely needs to invoke a standard functional endpoint. The post-exploitation impact includes the loss of confidentiality regarding user interaction data, which may be exploited for reconnaissance, tracking user activity, or social engineering purposes within the environment."
}
CVE-2026-108887: JeecgBoot Missing Authorization in ExportXls (MEDIUM Severity, CVSS: 4.3) | Sceawere