Sceawere
Vulnerability Detail
CVE-2026-108891UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
JeecgBoot Broken Access Control Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 3h ago
- Vendor
- jeecgboot
- Product
- JeecgBoot
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysUserController getUserDetailByUserId handler that allows any authenticated user to read other users' details. Low-privileged attackers can supply arbitrary userId values to retrieve real names, usernames, emails, phone numbers, birthdays, employee numbers, department paths and posts.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-11T15:16:56.203Z",
"pubdate": "2026-10-11T15:16:56.203Z",
"executiveSummary": "JeecgBoot through version 3.9.5 is affected by a missing authorization vulnerability within the SysUserController component.\nThis flaw, categorized as a Broken Access Control issue, permits any authenticated user to perform unauthorized data retrieval of other users' sensitive personal information.\nThe vulnerability originates from a failure to enforce authorization checks on the getUserDetailByUserId handler.\nAn attacker with low-privileged access can leverage this flaw to harvest sensitive user data, including real names, usernames, email addresses, phone numbers, birthdays, employee numbers, department structures, and job posts.\nThe impact involves significant exposure of PII (Personally Identifiable Information) and organizational metadata, which could be utilized for secondary attacks such as social engineering, account enumeration, or unauthorized corporate reconnaissance.\nSuccessful exploitation requires the attacker to hold valid authentication credentials but does not require escalated administrative privileges, representing a high risk to data confidentiality across affected deployments.",
"technicalDetails": "The vulnerability resides within the SysUserController class in JeecgBoot, specifically affecting the implementation of the getUserDetailByUserId method. This handler is responsible for fetching user profile information based on a provided unique identifier.\nThe root cause of the vulnerability is an insufficient access control check. While the endpoint requires a session to be established, it fails to perform a validation check to ensure that the currently authenticated user is authorized to view the requested resource (the user details of a target UID).\nUnder standard security practices, an endpoint managing sensitive profile data should implement an object-level authorization mechanism. In this instance, the controller lacks the logic to verify if the requester has permission to access the specific user profile, or if the requester is the resource owner.\nThe attack flow proceeds as follows: 1. The attacker authenticates to the application using valid, low-privileged credentials. 2. Once the session is established, the attacker identifies the API endpoint associated with the getUserDetailByUserId handler. 3. The attacker constructs an HTTP request targeting this endpoint, substituting the 'userId' parameter with the identifier of an arbitrary target user. 4. Due to the lack of authorization enforcement, the backend service processes the request without validating ownership or permission, successfully executing a database query to retrieve the target user's sensitive record. 5. The application returns the complete user object in the JSON response, effectively leaking sensitive information to the unauthorized requester.\nThis vulnerability is particularly impactful because it allows for mass enumeration of the user database. An attacker can automate the exploitation process by iterating through sequential or known user identifiers to compile a comprehensive repository of internal employee or user records. The information exposed—specifically department paths and employee numbers—is highly valuable for crafting sophisticated phishing campaigns or performing lateral movement within an organization's internal ecosystem. The lack of input validation or authorization checks at this specific handler provides a direct conduit for unauthorized data exfiltration within the scope of the authenticated user's session."
}