JeecgBoot through 3.9.5 contains a missing authorization vulnerability in SysDepartPermissionController that allows any authenticated user to modify department permission records by calling the edit endpoint. Low-privileged attackers can obtain row ids from the unguarded list endpoint and overwrite depart_id, permission_id and data_rule_ids to alter which menus and data rules departments may delegate.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 11 Oct 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jeecg jeecg-boot
|
|
| Vendors & Products |
Jeecg jeecg-boot
|
Sat, 10 Oct 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | JeecgBoot through 3.9.5 contains a missing authorization vulnerability in SysDepartPermissionController that allows any authenticated user to modify department permission records by calling the edit endpoint. Low-privileged attackers can obtain row ids from the unguarded list endpoint and overwrite depart_id, permission_id and data_rule_ids to alter which menus and data rules departments may delegate. | |
| Title | JeecgBoot through 3.9.5 Missing Authorization via /sys/sysDepartPermission/edit | |
| First Time appeared |
Jeecg
Jeecg jeecg Boot |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jeecg
Jeecg jeecg Boot |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-10T21:49:25.348Z
Reserved: 2026-10-10T20:18:19.617Z
Link: CVE-2026-108630
No data.
Status : Received
Published: 2026-10-10T22:16:37.873
Modified: 2026-10-10T22:16:37.873
Link: CVE-2026-108630
No data.
OpenCVE Enrichment
Updated: 2026-10-11T05:45:16Z
Weaknesses