VYPR
Medium severity4.3NVD Advisory· Published Oct 11, 2026

CVE-2026-108869

CVE-2026-108869

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to send system announcements by calling POST /sys/api/sendSysAnnouncement. Attackers can supply arbitrary title, content, fromUser and toUser values to deliver forged announcements to any users via WebSocket, WeCom, DingTalk and Feishu.

Affected products

1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.