Sceawere

Vulnerability Detail

CVE-2026-108891UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

JeecgBoot Broken Access Control Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
jeecgboot
Product
JeecgBoot
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysUserController getUserDetailByUserId handler that allows any authenticated user to read other users' details. Low-privileged attackers can supply arbitrary userId values to retrieve real names, usernames, emails, phone numbers, birthdays, employee numbers, department paths and posts.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-11T15:16:56.203Z",
  "pubdate": "2026-10-11T15:16:56.203Z",
  "executiveSummary": "JeecgBoot through version 3.9.5 is affected by a missing authorization vulnerability within the SysUserController component.\nThis flaw, categorized as a Broken Access Control issue, permits any authenticated user to perform unauthorized data retrieval of other users' sensitive personal information.\nThe vulnerability originates from a failure to enforce authorization checks on the getUserDetailByUserId handler.\nAn attacker with low-privileged access can leverage this flaw to harvest sensitive user data, including real names, usernames, email addresses, phone numbers, birthdays, employee numbers, department structures, and job posts.\nThe impact involves significant exposure of PII (Personally Identifiable Information) and organizational metadata, which could be utilized for secondary attacks such as social engineering, account enumeration, or unauthorized corporate reconnaissance.\nSuccessful exploitation requires the attacker to hold valid authentication credentials but does not require escalated administrative privileges, representing a high risk to data confidentiality across affected deployments.",
  "technicalDetails": "The vulnerability resides within the SysUserController class in JeecgBoot, specifically affecting the implementation of the getUserDetailByUserId method. This handler is responsible for fetching user profile information based on a provided unique identifier.\nThe root cause of the vulnerability is an insufficient access control check. While the endpoint requires a session to be established, it fails to perform a validation check to ensure that the currently authenticated user is authorized to view the requested resource (the user details of a target UID).\nUnder standard security practices, an endpoint managing sensitive profile data should implement an object-level authorization mechanism. In this instance, the controller lacks the logic to verify if the requester has permission to access the specific user profile, or if the requester is the resource owner.\nThe attack flow proceeds as follows: 1. The attacker authenticates to the application using valid, low-privileged credentials. 2. Once the session is established, the attacker identifies the API endpoint associated with the getUserDetailByUserId handler. 3. The attacker constructs an HTTP request targeting this endpoint, substituting the 'userId' parameter with the identifier of an arbitrary target user. 4. Due to the lack of authorization enforcement, the backend service processes the request without validating ownership or permission, successfully executing a database query to retrieve the target user's sensitive record. 5. The application returns the complete user object in the JSON response, effectively leaking sensitive information to the unauthorized requester.\nThis vulnerability is particularly impactful because it allows for mass enumeration of the user database. An attacker can automate the exploitation process by iterating through sequential or known user identifiers to compile a comprehensive repository of internal employee or user records. The information exposed—specifically department paths and employee numbers—is highly valuable for crafting sophisticated phishing campaigns or performing lateral movement within an organization's internal ecosystem. The lack of input validation or authorization checks at this specific handler provides a direct conduit for unauthorized data exfiltration within the scope of the authenticated user's session."
}
CVE-2026-108891: JeecgBoot Broken Access Control Vulnerability (MEDIUM Severity, CVSS: 4.3) | Sceawere