PatchSiren cyber security CVE debrief
CVE-2026-108653 jeecgboot CVE debrief
CVE-2026-108653 is a missing authorization vulnerability in JeecgBoot through version 3.9.5, specifically in the queryPageList handler of OpenApiController. This allows any authenticated user to list OpenAPI registry definitions. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Low-privileged attackers can query GET /openapi/list to read virtual paths, internal origin URLs, IP whitelists, and header and parameter templates intended for administrators.
- Vendor
- jeecgboot
- Product
- Unknown
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders who are responsible for systems using JeecgBoot version 3.9.5 or earlier should assess their exposure and take necessary actions to prevent exploitation. This includes verifying if their systems are using the affected version, assessing the impact of the vulnerability on their systems, and restricting access to the OpenAPI registry definitions. Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their
Why it matters
CVE-2026-108653 is a missing authorization vulnerability in JeecgBoot through version 3.9.5 that allows any authenticated user to list OpenAPI registry definitions. Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their systems.
- Low-privileged attackers can read virtual paths, internal origin URLs, IP whitelists, and header and parameter templates intended for administrators.
- Defenders need to verify if their systems are using JeecgBoot version 3.9.5 or earlier.
- Defenders need to assess the impact of the vulnerability on their systems.
- Defenders need to restrict access to the OpenAPI registry definitions.
Technical summary
The vulnerability is caused by a missing authorization check in the queryPageList handler of OpenApiController in JeecgBoot through version 3.9.5. This allows any authenticated user to list OpenAPI registry definitions by querying GET /openapi/list. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Low-privileged attackers can query to read virtual paths, internal origin URLs, IP whitelists, and header and parameter templates intended for administrators. The vulnerability affects JeecgBoot through version 3.9.5.
Defensive priority
Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their systems, especially if they are using JeecgBoot version 3.9.5 or earlier.
Recommended defensive actions
- Verify if the system is using JeecgBoot version 3.9.5 or earlier
- Assess the impact of the vulnerability on the system
- Restrict access to the OpenAPI registry definitions
- Monitor for potential exploitation attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The evidence for this vulnerability comes from the CVE Program record, the NVD vulnerability detail page, and source references provided by [email protected]. The CVE record was published on 2026-10-10T22:16:41.347Z and has not been modified since then. The vulnerability has been confirmed in JeecgBoot through version 3.9.5. Limited source information is available, so defenders should verify exposure with explicit evidence and defensive verification tasks.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108653 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108653
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108653 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108653
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/JeecgBoot/poc_openapi_config_and_call_gateway.py
-
Source reference
Unverified legacy reference
URL: https://github.com/jeecgboot/JeecgBoot/blob/e3b9dc0aefe1943d9772b026f64ed671a7c82802/jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/openapi/controller/OpenApiController.java
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/jeecgboot-through-3.9.5-missing-authorization-via-get-openapi-list
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.