PatchSiren cyber security CVE debrief
CVE-2026-108649 jeecgboot CVE debrief
CVE-2026-108649 is a missing authorization vulnerability in JeecgBoot through 3.9.5, specifically in the queryUserRolesById handler of SystemApiController. This allows authenticated users to read any user's role codes. Low-privileged attackers can exploit this by sending a userId to GET /sys/api/queryUserRolesById, enabling them to enumerate role assignments and identify administrator accounts.
- Vendor
- jeecgboot
- Product
- Unknown
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
System administrators and security teams responsible for JeecgBoot installations, especially those with low-privileged user accounts, should assess exposure and prioritize mitigation to prevent potential role enumeration and unauthorized access.
Why it matters
CVE-2026-108649 is a medium-severity vulnerability in JeecgBoot that allows authenticated users to enumerate role assignments. Defenders should verify exposure, especially in systems with low-privileged accounts, and prioritize mitigation to prevent potential unauthorized access and privilege escalation.
- Role enumeration and potential privilege escalation.
- Unauthorized access to sensitive role information.
- Increased risk of targeted attacks using enumerated role assignments.
- Potential for lateral movement within compromised systems.
Technical summary
The queryUserRolesById handler in SystemApiController of JeecgBoot through 3.9.5 does not properly enforce authorization, allowing authenticated users to read role codes of any user by sending a crafted request to GET /sys/api/queryUserRolesById with a userId parameter. This vulnerability enables low-privileged attackers to enumerate role assignments and identify administrator accounts, potentially leading to privilege escalation or unauthorized access. Defenders should verify exposure, especially in systems with low-privileged accounts, and prioritize mitigation to prevent potential unauthorized access and privilege escalation.
Defensive priority
Defenders should prioritize verifying and mitigating this vulnerability, especially in systems where role enumeration could lead to privilege escalation or unauthorized access.
Recommended defensive actions
- Verify the version of JeecgBoot in use and check if it is vulnerable (3.9.5 or earlier).
- Restrict access to the /sys/api/queryUserRolesById endpoint to authorized users only.
- Implement additional monitoring to detect and respond to potential exploitation attempts.
- Consider upgrading to a version of JeecgBoot that addresses this vulnerability, if available.
- Review system configurations for potential exposure.
- Conduct a thorough review of role assignments and user privileges.
- Monitor for suspicious activity related to role enumeration.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability in JeecgBoot through 3.9.5. The queryUserRolesById handler in SystemApiController does not properly enforce authorization, allowing authenticated users to read role codes of any user. However, the exact scope of affected systems and versions beyond 3.9.5 is not specified, requiring further verification and defensive review of system configurations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108649 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108649
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108649 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108649
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/JeecgBoot/poc_sys_api_user_roles_by_id.py
-
Source reference
Unverified legacy reference
URL: https://github.com/jeecgboot/JeecgBoot/blob/e3b9dc0aefe1943d9772b026f64ed671a7c82802/jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/api/controller/SystemApiController.java
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/jeecgboot-through-3.9.5-missing-authorization-via-sys-api-queryuserrolesbyid
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.