PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108646 jeecgboot CVE debrief

CVE-2026-108646 is a missing authorization vulnerability in JeecgBoot through 3.9.5, specifically in the SysCategoryController importExcel handler. This allows any authenticated user to import category dictionary entries. Low-privileged attackers can upload crafted Excel workbooks to bulk insert arbitrary nodes into the system-wide sys_category dictionary, including under existing parent nodes.

Vendor
jeecgboot
Product
Unknown
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

System administrators, security teams, and developers using JeecgBoot should assess their exposure and prioritize remediation. This vulnerability is particularly concerning for systems where low-privileged users have access to the SysCategoryController importExcel handler.

Why it matters

CVE-2026-108646 is a missing authorization vulnerability in JeecgBoot through 3.9.5. Low-privileged attackers can exploit this to import arbitrary category dictionary entries. Defenders should prioritize verification, remediation, and monitoring to prevent potential data insertion and system disruption.

  • Potential for unauthorized data insertion into the sys_category dictionary.
  • Possible disruption of system functionality due to arbitrary node insertion.
  • Need for verification of affected versions and exposure.
  • Priority for remediation to prevent exploitation.

Technical summary

The vulnerability exists in the SysCategoryController importExcel handler of JeecgBoot through 3.9.5. This handler allows any authenticated user to import category dictionary entries without proper authorization. Low-privileged attackers can exploit this by uploading crafted Excel workbooks to bulk insert arbitrary nodes into the system-wide sys_category dictionary. Affected product context requires verification of JeecgBoot versions 3.9.5 or earlier. Defenders should prioritize verifying and remediating this vulnerability, especially in systems where low-privileged users have access to the SysCategoryController importExcel handler.

Defensive priority

Defenders should prioritize verifying and remediating this vulnerability, especially in systems where low-privileged users have access to the SysCategoryController importExcel handler.

Recommended defensive actions

  • Verify the version of JeecgBoot being used and assess if it is vulnerable (3.9.5 or earlier).
  • Restrict access to the SysCategoryController importExcel handler to authorized users only.
  • Monitor for suspicious Excel workbook uploads and system-wide sys_category dictionary changes.
  • Implement additional logging and auditing to detect potential exploitation attempts.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Evidence notes

The CVE record and NVD entry provide details about the vulnerability. However, the exact scope of affected systems and versions requires further verification from the official sources. Affected product deployments should be confirmed to exist in managed environments, and an owner should be assigned for follow-up. The official advisory or CVE record should be reviewed to validate affected scope, severity, and vendor guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108646 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108646

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108646 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108646

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/JeecgBoot/poc_c083_category_import_xlsx.py

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://github.com/jeecgboot/JeecgBoot/blob/e3b9dc0aefe1943d9772b026f64ed671a7c82802/jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysCategoryController.java

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/jeecgboot-through-3.9.5-missing-authorization-via-sys-category-importexcel

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.