PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-75479 jeecgboot CVE debrief

CVE-2026-75479 debrief based on the supplied source corpus. The CVE record was published on 2026-08-17T21:16:50.333Z and has not been modified since then. This high-severity authentication bypass vulnerability in JimuReport allows unauthenticated attackers to enumerate reports and retrieve share tokens, potentially leading to exposure of report definitions and live query data. Defenders should prioritize verifying exposure, assessing impact, and updating access controls to mitigate potential risks. The CVE record and NVD entry provide details on the authentication bypass vulnerability in JimuReport. However, the corpus does not establish versions, exploitation, impact, or specific

Vendor
jeecgboot
Product
jimureport
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-17
Original CVE updated
2026-09-24
Advisory published
2026-08-17
Advisory updated
2026-09-24

Who should care

Defenders responsible for JimuReport installations, security teams assessing exposure to report endpoints, and administrators of systems using JimuReport should be aware of this vulnerability and take steps to verify exposure and mitigate potential risks.

Why it matters

CVE-2026-75479 is a high-severity authentication bypass vulnerability in JimuReport that allows unauthenticated attackers to enumerate reports and retrieve share tokens, potentially leading to exposure of report definitions and live query data. Defenders should prioritize verifying exposure, assessing impact, and updating access controls to mitigate potential risks.

  • Potential exposure of report definitions and live query data
  • Possible unauthorized access to protected report endpoints
  • Risk of data breaches due to disclosed share tokens
  • Need for verification of JimuReport installations and access controls

Technical summary

JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint, allowing unauthenticated attackers to enumerate all reports and retrieve share tokens. These share tokens can be used to access protected report endpoints and retrieve full report definitions, including embedded SQL statements and live query data. The vulnerability has a CVSS score of 8.7 and is classified as HIGH severity. The CVE record and NVD entry provide details on the authentication bypass vulnerability in JimuReport, but do not provide information on versions, exploitation, impact, or remediation. Defenders should prioritize verifying exposure of JimuReport installations to unauthenticated report

Defensive priority

Defenders should prioritize verifying exposure of JimuReport installations to unauthenticated report listing and share token disclosure, assessing the impact of potential report definition and live query data exposure.

Recommended defensive actions

  • Verify exposure of JimuReport installations to unauthenticated report listing and share token disclosure
  • Assess the impact of potential report definition and live query data exposure
  • Review and update access controls for report endpoints
  • Monitor for potential unauthorized access to protected report endpoints
  • Confirm whether affected JimuReport deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The CVE record and NVD entry provide details on the authentication bypass vulnerability in JimuReport. However, the corpus does not establish versions, exploitation, impact, or remediation, requiring verification from the supplied official sources.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-75479 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-75479

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-75479 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75479

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.