PatchSiren cyber security CVE debrief
CVE-2026-108632 jeecgboot CVE debrief
CVE-2026-108632 is a missing authorization vulnerability in JeecgBoot through 3.9.5, specifically in the SysDepartPermissionController queryById handler. This allows any authenticated user to read department permission records. Low-privileged attackers can exploit this by requesting GET /sys/sysDepartPermission/queryById with arbitrary ids to retrieve depart_id, permission_id, and data_rule_ids for any department.
- Vendor
- jeecgboot
- Product
- Unknown
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders and administrators of systems using JeecgBoot, especially those with low-privileged user access, should assess exposure and prioritize remediation. They should verify the version of JeecgBoot being used, assess if it is vulnerable, and implement compensating controls for exposed systems while remediation is scheduled and verified.
Why it matters
CVE-2026-108632 is a missing authorization vulnerability in JeecgBoot through 3.9.5 that allows low-privileged attackers to read department permission records. Defenders should prioritize verifying and remediating this vulnerability, especially in systems where low-privileged users have access to sensitive information. The exact scope of affected systems and versions requires further verification from official sources.
- Potential unauthorized access to sensitive department permission records.
- Increased risk of data breaches due to low-privileged user exploitation.
- Need for verification of affected versions and systems.
- Priority for remediation and compensating controls.
Technical summary
The vulnerability exists in the SysDepartPermissionController queryById handler of JeecgBoot through 3.9.5. This handler fails to properly authorize requests, allowing any authenticated user to read department permission records by requesting GET /sys/sysDepartPermission/queryById with arbitrary ids. This allows low-privileged attackers to retrieve depart_id, permission_id, and data_rule_ids for any department, potentially leading to unauthorized access to sensitive department permission records and increased risk of data breaches.
Defensive priority
Defenders should prioritize verifying and remediating this vulnerability, especially in systems where low-privileged users have access to sensitive information.
Recommended defensive actions
- Verify the version of JeecgBoot being used and assess if it is vulnerable.
- Restrict access to the SysDepartPermissionController queryById handler to authorized users only.
- Monitor for any suspicious activity related to department permission records.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and NVD entry provide details about the vulnerability in JeecgBoot through 3.9.5. However, the exact scope of affected systems and versions requires further verification from the official sources. Defenders should verify the version of JeecgBoot being used, assess if it is vulnerable, and prioritize remediation, especially in systems where low-privileged users have access to sensitive information.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108632 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108632
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108632 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108632
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/JeecgBoot/poc_depart_permission_query_by_id.py
-
Source reference
Unverified legacy reference
URL: https://github.com/jeecgboot/JeecgBoot/blob/e3b9dc0aefe1943d9772b026f64ed671a7c82802/jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysDepartPermissionController.java
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/jeecgboot-through-3.9.5-missing-authorization-via-sysdepartpermission-querybyid-endpoint
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.