Sceawere
Vulnerability Detail
CVE-2026-108888UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
JeecgBoot Missing Authorization in exportXls
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 3h ago
- Vendor
- jeecgboot
- Product
- JeecgBoot
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysDepartRoleController exportXls handler that allows any authenticated user to export department roles. Low-privileged attackers holding only the default minimal role can call /sys/sysDepartRole/exportXls to download all sys_depart_role records, including role names, codes, descriptions and creating users.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-11T15:16:56.067Z",
"pubdate": "2026-10-11T15:16:56.067Z",
"executiveSummary": "JeecgBoot versions through 3.9.5 are susceptible to a missing authorization vulnerability within the SysDepartRoleController. The vulnerability resides in the exportXls handler, which fails to enforce adequate access control checks for the export operation. This flaw permits any authenticated user, regardless of their privilege level or assigned roles, to invoke the endpoint and extract sensitive data contained within the sys_depart_role table.\nThe impact of this vulnerability is categorized as an insecure direct object reference or broken access control, leading to unauthorized information disclosure. By exploiting this flaw, low-privileged attackers can obtain an inventory of department roles, including internal role codes, descriptions, and metadata regarding the users who created these entities. This exposure of organizational architecture and internal nomenclature poses a significant risk to administrative security and reconnaissance for further malicious activities. Exploitation requires minimal effort, as it only necessitates a valid session on the target platform, making it a viable target for internal threats or compromised low-privilege accounts.",
"technicalDetails": "The root cause of this vulnerability is the absence of robust authorization logic within the SysDepartRoleController's exportXls method. In the JeecgBoot architecture, the controller handler is designed to generate and return spreadsheet exports for administrative auditing or data management purposes. However, the implementation lacks an explicit permission check or role-based access control (RBAC) validation against the current user's session context during the invocation of the export routine.\nSpecifically, the /sys/sysDepartRole/exportXls endpoint is reachable by any user possessing a legitimate session token. Because the backend code does not verify whether the authenticated identity possesses the 'sys_depart_role:export' or equivalent administrative permission before initiating the database query and file serialization, the application serves the requested sensitive data indiscriminately.\nThe attack flow proceeds as follows: First, the attacker authenticates to the JeecgBoot instance using valid, low-privileged credentials, such as a default minimal user account. Second, the attacker interacts directly with the /sys/sysDepartRole/exportXls endpoint via a standard HTTP GET or POST request. Third, the controller maps this request to the vulnerable exportXls function. Fourth, the function performs a query to the underlying database to retrieve records from the sys_depart_role table without filtering or authorization checks. Finally, the server streams the exported data (typically in XLS or XLSX format) back to the attacker's client.\nThe exposed data set is comprehensive, encompassing role names, unique role codes, detailed descriptions, and audit-related metadata such as the identifiers of the users who created these roles. This information is highly valuable for reconnaissance, as it provides an attacker with a mapping of internal departmental structures and potential administrative naming conventions within the organization. The vulnerability affects all versions of JeecgBoot up to and including 3.9.5. Given that the component operates within the standard web application lifecycle, the vulnerability is accessible via the network segment exposed to the application. Post-exploitation, an attacker gains visibility into the backend data structure, which can be leveraged to refine further attacks against specific high-value administrative accounts or to identify targeted roles for potential privilege escalation attempts through other vector paths."
}