Skip to content
JeecgBoot 3.9.5 Vulnerabilities: Missing Authorization Issues

JeecgBoot 3.9.5 Vulnerabilities: Missing Authorization Issues

First seen 11 Oct 2026, 10:32 UTC •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 11, 2026 at 17:31 UTC
  • •JeecgBoot versions up to 3.9.5 have critical missing authorization vulnerabilities.
  • •Unauthorized access to sensitive functions is possible via specific endpoints.
  • •No active exploitation reported, but proof-of-concept code exists.

Two vulnerabilities have been identified in JeecgBoot versions up to 3.9.5, specifically in the saveDeptRolePermission and sysTenantPassapply endpoints. These vulnerabilities involve missing authorization checks, allowing unauthorized users to access sensitive functionalities. The issues are categorized under CWE-862, indicating a lack of proper authorization controls. Affected organizations using JeecgBoot should prioritize remediation to prevent potential exploitation. Currently, there is no indication of in the wild, but the existence of proof-of-concept code raises concerns. Security teams are advised to assess their systems and apply necessary updates if available. The vulnerabilities were disclosed on October 11, 2026, coinciding with the publication of advisories.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-11
Vulnerabilities disclosed
JeecgBoot vulnerabilities related to missing authorization were publicly disclosed, affecting versions up to 3.9.5.
VulnCheck
2026-10-11
Second vulnerability disclosed
Another missing authorization vulnerability in JeecgBoot was disclosed, affecting the sysTenantPassapply endpoint.
VulnCheck

More articles in this cluster (2)

Common questions

What versions of JeecgBoot are affected?
JeecgBoot versions up to 3.9.5 are affected by these vulnerabilities.
Is there any active exploitation of these vulnerabilities?
Currently, there is no confirmed active exploitation reported, but proof-of-concept code is available.
What should organizations do to mitigate these vulnerabilities?
Organizations should assess their use of JeecgBoot and apply any available patches or mitigations as soon as possible.