JeecgBoot: 25 Missing Authorization Vulnerabilities Disclosed Together
Key findings • 25 missing authorization vulnerabilities disclosed in JeecgBoot v3.9.5. • High-severity flaws include password retrieval (CVE-2026-108677) and tenant ownership transfer (CVE-20…
Key findings
- 25 missing authorization vulnerabilities disclosed in JeecgBoot v3.9.5.
- High-severity flaws include password retrieval (CVE-2026-108677) and tenant ownership transfer (CVE-2026-108662).
- Critical vulnerabilities allow tenant admin approval (CVE-2026-108657) and unauthorized access to AI data.
- Vulnerabilities span system announcements, user management, AI features, and tenant administration.
- All affected versions are through 3.9.5; update recommended.
On October 10, 2026, a batch of 25 medium-severity vulnerabilities was disclosed in JeecgBoot through version 3.9.5. These vulnerabilities primarily stem from missing authorization checks, allowing authenticated users with low privileges to access or manipulate data and functionalities beyond their intended scope. The disclosures highlight a widespread issue with access control within the application.
The vulnerabilities can be broadly categorized by the affected modules and their impact:
System Announcements and Notifications
Several CVEs relate to the handling of system announcements. CVE-2026-108680 and CVE-2026-108679 allow any authenticated user to send template and bus announcements, respectively, with forged sender and recipient information. Additionally, CVE-2026-108676 permits low-privileged users to download attachments from unreleased announcements, and CVE-2026-108675 enables them to alter the pin status of announcements.
User and Role Management
CVE-2026-108678 allows authenticated users to query the roles of any user, potentially enumerating role assignments. A more critical vulnerability, CVE-2026-108677 (rated High), allows low-privileged users to retrieve any user's password, which is AES-CBC protected and can be decrypted using a hard-coded key. This could lead to the compromise of administrative credentials. Another vulnerability, CVE-2026-108662, allows any authenticated user to transfer tenant ownership by reassigning the owner of any tenant.
AI and Prompt Management
A significant number of vulnerabilities affect the AI and prompt management features. These include:
- Unauthorized export of all AI prompts (CVE-2026-108673).
- Access to other users' AI video generation records (CVE-2026-108672).
- Reading MCP server configurations, including endpoint URLs and headers (CVE-2026-108671).
- Running AI prompt experiments using other users' data (CVE-2026-108670).
- Reading document text chunks from knowledge bases (CVE-2026-108669).
- Purging AI prompt templates from the recycle bin (CVE-2026-108668).
- Restoring deleted AI prompt templates (CVE-2026-108667).
- Deleting AI prompt templates (CVE-2026-108666).
- Modifying AI prompt templates (CVE-2026-108665).
- Reading any AI prompt template (CVE-2026-108664).
Tenant Management
Several vulnerabilities impact tenant management functionalities:
- Rejecting tenant administrator applications (CVE-2026-108663).
- Removing users from tenant product packs (CVE-2026-108662).
- Modifying tenant settings, including enabling or disabling applications (CVE-2026-108660).
- Querying tenant product pack configurations (CVE-2026-108659).
- Reading other tenants' records (CVE-2026-10858).
- Approving tenant administrator applications (CVE-2026-108657, rated High).
- Reading tenant administrator applications (CVE-2026-108656).
Other Vulnerabilities
CVE-2026-108674 allows low-privileged users to read OpenAPI definitions, exposing internal origin URLs and virtual host information.
All disclosed vulnerabilities affect JeecgBoot versions through 3.9.5. Users are advised to update to a patched version as soon as possible to mitigate these risks. The consistent pattern of missing authorization checks across various modules indicates a need for thorough security reviews of access control mechanisms in future development.
The batch of 25 vulnerabilities disclosed on October 10, 2026, underscores significant authorization flaws in JeecgBoot through version 3.9.5. The consistent nature of these vulnerabilities, primarily missing authorization checks, allows authenticated low-privileged users to perform actions and access data outside their intended permissions. This broad exposure necessitates immediate attention from users of JeecgBoot.
The vulnerabilities impact several key areas, including system announcements, user and role management, AI features, and tenant administration. Notably, CVE-2026-108677 and CVE-2026-108657, both rated High, present particularly severe risks, allowing for the retrieval of user passwords and the approval of tenant administrator applications, respectively. The widespread nature of these issues suggests a systemic problem with access control implementation within the affected versions of JeecgBoot. Users should prioritize updating their systems to a secure version.