PatchSiren cyber security CVE debrief
CVE-2026-108646 jeecgboot CVE debrief
CVE-2026-108646 is a missing authorization vulnerability in JeecgBoot through 3.9.5, specifically in the SysCategoryController importExcel handler. This allows any authenticated user to import category dictionary entries. Low-privileged attackers can upload crafted Excel workbooks to bulk insert arbitrary nodes into the system-wide sys_category dictionary, including under existing parent nodes.
- Vendor
- jeecgboot
- Product
- Unknown
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
System administrators, security teams, and developers using JeecgBoot should assess their exposure and prioritize remediation. This vulnerability is particularly concerning for systems where low-privileged users have access to the SysCategoryController importExcel handler.
Why it matters
CVE-2026-108646 is a missing authorization vulnerability in JeecgBoot through 3.9.5. Low-privileged attackers can exploit this to import arbitrary category dictionary entries. Defenders should prioritize verification, remediation, and monitoring to prevent potential data insertion and system disruption.
- Potential for unauthorized data insertion into the sys_category dictionary.
- Possible disruption of system functionality due to arbitrary node insertion.
- Need for verification of affected versions and exposure.
- Priority for remediation to prevent exploitation.
Technical summary
The vulnerability exists in the SysCategoryController importExcel handler of JeecgBoot through 3.9.5. This handler allows any authenticated user to import category dictionary entries without proper authorization. Low-privileged attackers can exploit this by uploading crafted Excel workbooks to bulk insert arbitrary nodes into the system-wide sys_category dictionary. Affected product context requires verification of JeecgBoot versions 3.9.5 or earlier. Defenders should prioritize verifying and remediating this vulnerability, especially in systems where low-privileged users have access to the SysCategoryController importExcel handler.
Defensive priority
Defenders should prioritize verifying and remediating this vulnerability, especially in systems where low-privileged users have access to the SysCategoryController importExcel handler.
Recommended defensive actions
- Verify the version of JeecgBoot being used and assess if it is vulnerable (3.9.5 or earlier).
- Restrict access to the SysCategoryController importExcel handler to authorized users only.
- Monitor for suspicious Excel workbook uploads and system-wide sys_category dictionary changes.
- Implement additional logging and auditing to detect potential exploitation attempts.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
The CVE record and NVD entry provide details about the vulnerability. However, the exact scope of affected systems and versions requires further verification from the official sources. Affected product deployments should be confirmed to exist in managed environments, and an owner should be assigned for follow-up. The official advisory or CVE record should be reviewed to validate affected scope, severity, and vendor guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108646 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108646
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108646 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108646
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/JeecgBoot/poc_c083_category_import_xlsx.py
-
Source reference
Unverified legacy reference
URL: https://github.com/jeecgboot/JeecgBoot/blob/e3b9dc0aefe1943d9772b026f64ed671a7c82802/jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysCategoryController.java
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/jeecgboot-through-3.9.5-missing-authorization-via-sys-category-importexcel
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.