PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108649 jeecgboot CVE debrief

CVE-2026-108649 is a missing authorization vulnerability in JeecgBoot through 3.9.5, specifically in the queryUserRolesById handler of SystemApiController. This allows authenticated users to read any user's role codes. Low-privileged attackers can exploit this by sending a userId to GET /sys/api/queryUserRolesById, enabling them to enumerate role assignments and identify administrator accounts.

Vendor
jeecgboot
Product
Unknown
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

System administrators and security teams responsible for JeecgBoot installations, especially those with low-privileged user accounts, should assess exposure and prioritize mitigation to prevent potential role enumeration and unauthorized access.

Why it matters

CVE-2026-108649 is a medium-severity vulnerability in JeecgBoot that allows authenticated users to enumerate role assignments. Defenders should verify exposure, especially in systems with low-privileged accounts, and prioritize mitigation to prevent potential unauthorized access and privilege escalation.

  • Role enumeration and potential privilege escalation.
  • Unauthorized access to sensitive role information.
  • Increased risk of targeted attacks using enumerated role assignments.
  • Potential for lateral movement within compromised systems.

Technical summary

The queryUserRolesById handler in SystemApiController of JeecgBoot through 3.9.5 does not properly enforce authorization, allowing authenticated users to read role codes of any user by sending a crafted request to GET /sys/api/queryUserRolesById with a userId parameter. This vulnerability enables low-privileged attackers to enumerate role assignments and identify administrator accounts, potentially leading to privilege escalation or unauthorized access. Defenders should verify exposure, especially in systems with low-privileged accounts, and prioritize mitigation to prevent potential unauthorized access and privilege escalation.

Defensive priority

Defenders should prioritize verifying and mitigating this vulnerability, especially in systems where role enumeration could lead to privilege escalation or unauthorized access.

Recommended defensive actions

  • Verify the version of JeecgBoot in use and check if it is vulnerable (3.9.5 or earlier).
  • Restrict access to the /sys/api/queryUserRolesById endpoint to authorized users only.
  • Implement additional monitoring to detect and respond to potential exploitation attempts.
  • Consider upgrading to a version of JeecgBoot that addresses this vulnerability, if available.
  • Review system configurations for potential exposure.
  • Conduct a thorough review of role assignments and user privileges.
  • Monitor for suspicious activity related to role enumeration.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in JeecgBoot through 3.9.5. The queryUserRolesById handler in SystemApiController does not properly enforce authorization, allowing authenticated users to read role codes of any user. However, the exact scope of affected systems and versions beyond 3.9.5 is not specified, requiring further verification and defensive review of system configurations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108649 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108649

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108649 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108649

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/JeecgBoot/poc_sys_api_user_roles_by_id.py

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://github.com/jeecgboot/JeecgBoot/blob/e3b9dc0aefe1943d9772b026f64ed671a7c82802/jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/api/controller/SystemApiController.java

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/jeecgboot-through-3.9.5-missing-authorization-via-sys-api-queryuserrolesbyid

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.