www.vulncheck.com JeecgBoot 3.9.5 Vulnerabilities: Missing Authorization Issues
Article Content
- •JeecgBoot versions up to 3.9.5 have critical missing authorization vulnerabilities.
- •Unauthorized access to sensitive functions is possible via specific endpoints.
- •No active exploitation reported, but proof-of-concept code exists.
Two vulnerabilities have been identified in JeecgBoot versions up to 3.9.5, specifically in the saveDeptRolePermission and sysTenantPassapply endpoints. These vulnerabilities involve missing authorization checks, allowing unauthorized users to access sensitive functionalities. The issues are categorized under CWE-862, indicating a lack of proper authorization controls. Affected organizations using JeecgBoot should prioritize remediation to prevent potential exploitation. Currently, there is no indication of in the wild, but the existence of proof-of-concept code raises concerns. Security teams are advised to assess their systems and apply necessary updates if available. The vulnerabilities were disclosed on October 11, 2026, coinciding with the publication of advisories.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Common questions
What versions of JeecgBoot are affected?
Is there any active exploitation of these vulnerabilities?
What should organizations do to mitigate these vulnerabilities?
Continue Reading
High-Risk CVE-2026-108708 in Wukong_HRM Exposes Sensitive Employee Data A missing authorization vulnerability in Wukong_HRM, identified as CVE-2026-108708, allows low-privileged employees to access sensitive payroll information, including payslips and bank details. The flaw arises from commit 186115e, where EmployeeAspect improperly grants HR administrator roles to all callers, and…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…