PatchSiren cyber security CVE debrief
CVE-2026-108629 jeecgboot CVE debrief
CVE-2026-108629 is a missing authorization vulnerability in JeecgBoot through 3.9.5, specifically in the saveDatarule handler of SysDepartPermissionController. This allows any authenticated user to modify department data rules. Low-privileged attackers can send departId, permissionId, and dataRuleIds to POST /sys/sysDepartPermission/datarule to change, add, or clear data rules on any department-menu permission binding.
- Vendor
- jeecgboot
- Product
- Unknown
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders and administrators of JeecgBoot instances, especially those with low-privileged user accounts, should assess exposure and verify authorization checks on the affected endpoint.
Why it matters
CVE-2026-108629 is a missing authorization vulnerability in JeecgBoot through 3.9.5 that allows authenticated users to modify department data rules. Defenders should prioritize verifying and restricting access to the affected endpoint, especially for low-privileged users. The exact scope of affected versions and potential exploitation remains limited.
- Potential unauthorized modification of department data rules
- Increased risk of data tampering or unauthorized changes
- Need for verification of authorization checks on the affected endpoint
- Priority for defenders to restrict access to the endpoint
Technical summary
The vulnerability exists in the saveDatarule handler of SysDepartPermissionController in JeecgBoot through 3.9.5. This handler allows any authenticated user to modify department data rules by sending departId, permissionId, and dataRuleIds to the POST /sys/sysDepartPermission/datarule endpoint. Low-privileged attackers can exploit this vulnerability to change, add, or clear data rules on any department-menu permission binding. Defenders should prioritize verifying and restricting access to the affected endpoint, especially for low-privileged users, and implement proper authorization checks.
Defensive priority
Defenders should prioritize verifying and restricting access to the affected endpoint, especially for low-privileged users.
Recommended defensive actions
- Verify and restrict access to the /sys/sysDepartPermission/datarule endpoint
- Implement proper authorization checks for low-privileged users
- Monitor for suspicious activity on the affected endpoint
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details about the vulnerability in JeecgBoot through 3.9.5. The vulnerability exists in the saveDatarule handler of SysDepartPermissionController, allowing any authenticated user to modify department data rules. However, the exact scope of affected versions and potential exploitation remains limited. Defenders should verify and restrict access to the affected endpoint, especially for low-privileged users, and monitor for suspicious activity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108629 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108629
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108629 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108629
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/JeecgBoot/poc_depart_permission_datarule.py
-
Source reference
Unverified legacy reference
URL: https://github.com/jeecgboot/JeecgBoot/blob/e3b9dc0aefe1943d9772b026f64ed671a7c82802/jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysDepartPermissionController.java
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/jeecgboot-through-3.9.5-missing-authorization-via-sysdepartpermission-datarule-endpoint
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.