JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the saveDatarule handler of SysDepartPermissionController that allows any authenticated user to modify department data rules. Low-privileged attackers can send departId, permissionId and dataRuleIds to POST /sys/sysDepartPermission/datarule to change, add or clear data rules on any department-menu permission binding.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 11 Oct 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jeecg jeecg-boot
Jeecgboot Jeecgboot jeecgboot |
|
| Vendors & Products |
Jeecg jeecg-boot
Jeecgboot Jeecgboot jeecgboot |
Sat, 10 Oct 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the saveDatarule handler of SysDepartPermissionController that allows any authenticated user to modify department data rules. Low-privileged attackers can send departId, permissionId and dataRuleIds to POST /sys/sysDepartPermission/datarule to change, add or clear data rules on any department-menu permission binding. | |
| Title | JeecgBoot through 3.9.5 Missing Authorization via sysDepartPermission datarule Endpoint | |
| First Time appeared |
Jeecg
Jeecg jeecg Boot |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jeecg
Jeecg jeecg Boot |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-10T21:49:24.643Z
Reserved: 2026-10-10T20:18:19.274Z
Link: CVE-2026-108629
No data.
Status : Received
Published: 2026-10-10T22:16:37.730
Modified: 2026-10-10T22:16:37.730
Link: CVE-2026-108629
No data.
OpenCVE Enrichment
Updated: 2026-10-11T01:00:13Z
Weaknesses