PatchSiren cyber security CVE debrief
CVE-2026-108677 jeecgboot CVE debrief
CVE-2026-108677 is a missing authorization vulnerability in JeecgBoot through 3.9.5 that allows low-privileged authenticated users to retrieve any user's stored password value. The vulnerability exists in the GET /sys/api/getUserByName endpoint. Attackers can decrypt the AES-CBC protected response using a hard-coded key exposed by /sys/getEncryptedString to obtain administrators' password ciphertexts for offline guessing.
- Vendor
- jeecgboot
- Product
- Unknown
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
System administrators and security teams responsible for JeecgBoot installations should assess exposure and prioritize remediation. Low-privileged users with access to the affected endpoint are at risk.
Why it matters
CVE-2026-108677 is a high-severity vulnerability in JeecgBoot that allows low-privileged users to retrieve user passwords. Defenders should verify and remediate this vulnerability, especially in systems where low-privileged users have access to the affected endpoint. The vulnerability's impact includes potential password exposure, lateral movement, and increased risk of unauthorized access. Evidence is based on official CVE and NVD records, as well as source references from Vulncheck and GitHub.
- Password exposure for offline guessing
- Potential lateral movement through low-privileged user accounts
- Increased risk of unauthorized access to sensitive information
- Need for verification of affected versions and remediation status
Technical summary
The CVE-2026-108677 vulnerability allows low-privileged authenticated users to retrieve any user's stored password value through the GET /sys/api/getUserByName endpoint in JeecgBoot versions through 3.9.5. The passwords are protected by AES-CBC and can be decrypted using a hard-coded key exposed by /sys/getEncryptedString. Defenders should prioritize verifying and remediating this vulnerability, especially in systems where low-privileged users have access to the affected endpoint. Evidence is based on official CVE and NVD records, as well as source references from Vulncheck and GitHub.
Defensive priority
Defenders should prioritize verifying and remediating this vulnerability, especially in systems where low-privileged users have access to the affected endpoint.
Recommended defensive actions
- Verify the version of JeecgBoot being used and assess if it is vulnerable.
- Restrict access to the GET /sys/api/getUserByName endpoint to authorized users.
- Consider implementing additional security measures to protect user passwords.
- Monitor for any suspicious activity related to the affected endpoint.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The vulnerability was reported by [email protected] and is documented in the CVE Program record and the NVD vulnerability detail page. Additional details are provided in source references from GitHub and Vulncheck.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108677 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108677
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108677 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108677
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/JeecgBoot/poc_sys_api_credential_family.py
-
Source reference
Unverified legacy reference
URL: https://github.com/jeecgboot/JeecgBoot/blob/e3b9dc0aefe1943d9772b026f64ed671a7c82802/jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/api/controller/SystemApiController.java
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/jeecgboot-through-3.9.5-missing-authorization-via-sys-api-getuserbyname
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.