PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108653 jeecgboot CVE debrief

CVE-2026-108653 is a missing authorization vulnerability in JeecgBoot through version 3.9.5, specifically in the queryPageList handler of OpenApiController. This allows any authenticated user to list OpenAPI registry definitions. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Low-privileged attackers can query GET /openapi/list to read virtual paths, internal origin URLs, IP whitelists, and header and parameter templates intended for administrators.

Vendor
jeecgboot
Product
Unknown
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders who are responsible for systems using JeecgBoot version 3.9.5 or earlier should assess their exposure and take necessary actions to prevent exploitation. This includes verifying if their systems are using the affected version, assessing the impact of the vulnerability on their systems, and restricting access to the OpenAPI registry definitions. Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their

Why it matters

CVE-2026-108653 is a missing authorization vulnerability in JeecgBoot through version 3.9.5 that allows any authenticated user to list OpenAPI registry definitions. Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their systems.

  • Low-privileged attackers can read virtual paths, internal origin URLs, IP whitelists, and header and parameter templates intended for administrators.
  • Defenders need to verify if their systems are using JeecgBoot version 3.9.5 or earlier.
  • Defenders need to assess the impact of the vulnerability on their systems.
  • Defenders need to restrict access to the OpenAPI registry definitions.

Technical summary

The vulnerability is caused by a missing authorization check in the queryPageList handler of OpenApiController in JeecgBoot through version 3.9.5. This allows any authenticated user to list OpenAPI registry definitions by querying GET /openapi/list. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Low-privileged attackers can query to read virtual paths, internal origin URLs, IP whitelists, and header and parameter templates intended for administrators. The vulnerability affects JeecgBoot through version 3.9.5.

Defensive priority

Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their systems, especially if they are using JeecgBoot version 3.9.5 or earlier.

Recommended defensive actions

  • Verify if the system is using JeecgBoot version 3.9.5 or earlier
  • Assess the impact of the vulnerability on the system
  • Restrict access to the OpenAPI registry definitions
  • Monitor for potential exploitation attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The evidence for this vulnerability comes from the CVE Program record, the NVD vulnerability detail page, and source references provided by [email protected]. The CVE record was published on 2026-10-10T22:16:41.347Z and has not been modified since then. The vulnerability has been confirmed in JeecgBoot through version 3.9.5. Limited source information is available, so defenders should verify exposure with explicit evidence and defensive verification tasks.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108653 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108653

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108653 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108653

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/JeecgBoot/poc_openapi_config_and_call_gateway.py

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://github.com/jeecgboot/JeecgBoot/blob/e3b9dc0aefe1943d9772b026f64ed671a7c82802/jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/openapi/controller/OpenApiController.java

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/jeecgboot-through-3.9.5-missing-authorization-via-get-openapi-list

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.