PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108632 jeecgboot CVE debrief

CVE-2026-108632 is a missing authorization vulnerability in JeecgBoot through 3.9.5, specifically in the SysDepartPermissionController queryById handler. This allows any authenticated user to read department permission records. Low-privileged attackers can exploit this by requesting GET /sys/sysDepartPermission/queryById with arbitrary ids to retrieve depart_id, permission_id, and data_rule_ids for any department.

Vendor
jeecgboot
Product
Unknown
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders and administrators of systems using JeecgBoot, especially those with low-privileged user access, should assess exposure and prioritize remediation. They should verify the version of JeecgBoot being used, assess if it is vulnerable, and implement compensating controls for exposed systems while remediation is scheduled and verified.

Why it matters

CVE-2026-108632 is a missing authorization vulnerability in JeecgBoot through 3.9.5 that allows low-privileged attackers to read department permission records. Defenders should prioritize verifying and remediating this vulnerability, especially in systems where low-privileged users have access to sensitive information. The exact scope of affected systems and versions requires further verification from official sources.

  • Potential unauthorized access to sensitive department permission records.
  • Increased risk of data breaches due to low-privileged user exploitation.
  • Need for verification of affected versions and systems.
  • Priority for remediation and compensating controls.

Technical summary

The vulnerability exists in the SysDepartPermissionController queryById handler of JeecgBoot through 3.9.5. This handler fails to properly authorize requests, allowing any authenticated user to read department permission records by requesting GET /sys/sysDepartPermission/queryById with arbitrary ids. This allows low-privileged attackers to retrieve depart_id, permission_id, and data_rule_ids for any department, potentially leading to unauthorized access to sensitive department permission records and increased risk of data breaches.

Defensive priority

Defenders should prioritize verifying and remediating this vulnerability, especially in systems where low-privileged users have access to sensitive information.

Recommended defensive actions

  • Verify the version of JeecgBoot being used and assess if it is vulnerable.
  • Restrict access to the SysDepartPermissionController queryById handler to authorized users only.
  • Monitor for any suspicious activity related to department permission records.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and NVD entry provide details about the vulnerability in JeecgBoot through 3.9.5. However, the exact scope of affected systems and versions requires further verification from the official sources. Defenders should verify the version of JeecgBoot being used, assess if it is vulnerable, and prioritize remediation, especially in systems where low-privileged users have access to sensitive information.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108632 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108632

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108632 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108632

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/JeecgBoot/poc_depart_permission_query_by_id.py

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://github.com/jeecgboot/JeecgBoot/blob/e3b9dc0aefe1943d9772b026f64ed671a7c82802/jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysDepartPermissionController.java

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/jeecgboot-through-3.9.5-missing-authorization-via-sysdepartpermission-querybyid-endpoint

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.