PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108629 jeecgboot CVE debrief

CVE-2026-108629 is a missing authorization vulnerability in JeecgBoot through 3.9.5, specifically in the saveDatarule handler of SysDepartPermissionController. This allows any authenticated user to modify department data rules. Low-privileged attackers can send departId, permissionId, and dataRuleIds to POST /sys/sysDepartPermission/datarule to change, add, or clear data rules on any department-menu permission binding.

Vendor
jeecgboot
Product
Unknown
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders and administrators of JeecgBoot instances, especially those with low-privileged user accounts, should assess exposure and verify authorization checks on the affected endpoint.

Why it matters

CVE-2026-108629 is a missing authorization vulnerability in JeecgBoot through 3.9.5 that allows authenticated users to modify department data rules. Defenders should prioritize verifying and restricting access to the affected endpoint, especially for low-privileged users. The exact scope of affected versions and potential exploitation remains limited.

  • Potential unauthorized modification of department data rules
  • Increased risk of data tampering or unauthorized changes
  • Need for verification of authorization checks on the affected endpoint
  • Priority for defenders to restrict access to the endpoint

Technical summary

The vulnerability exists in the saveDatarule handler of SysDepartPermissionController in JeecgBoot through 3.9.5. This handler allows any authenticated user to modify department data rules by sending departId, permissionId, and dataRuleIds to the POST /sys/sysDepartPermission/datarule endpoint. Low-privileged attackers can exploit this vulnerability to change, add, or clear data rules on any department-menu permission binding. Defenders should prioritize verifying and restricting access to the affected endpoint, especially for low-privileged users, and implement proper authorization checks.

Defensive priority

Defenders should prioritize verifying and restricting access to the affected endpoint, especially for low-privileged users.

Recommended defensive actions

  • Verify and restrict access to the /sys/sysDepartPermission/datarule endpoint
  • Implement proper authorization checks for low-privileged users
  • Monitor for suspicious activity on the affected endpoint
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details about the vulnerability in JeecgBoot through 3.9.5. The vulnerability exists in the saveDatarule handler of SysDepartPermissionController, allowing any authenticated user to modify department data rules. However, the exact scope of affected versions and potential exploitation remains limited. Defenders should verify and restrict access to the affected endpoint, especially for low-privileged users, and monitor for suspicious activity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108629 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108629

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108629 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108629

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/JeecgBoot/poc_depart_permission_datarule.py

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://github.com/jeecgboot/JeecgBoot/blob/e3b9dc0aefe1943d9772b026f64ed671a7c82802/jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysDepartPermissionController.java

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/jeecgboot-through-3.9.5-missing-authorization-via-sysdepartpermission-datarule-endpoint

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.