CVE-2026-108632: JeecgBoot through 3.9.5 Missing Authorization via sysDepartPermission queryById Endpoint
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysDepartPermissionController queryById handler that allows any authenticated user to read department permission records. Low-privileged attackers can request GET /sys/sysDepartPermission/queryById with arbitrary ids to retrieve departid, permissionid and dataruleids for any department.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated JeecgBoot user, including a low-privileged account, can exploit it. The attacker only needs network access to the application and a valid user session or credentials.
What information can an attacker obtain?
An attacker can submit arbitrary record IDs to GET /sys/sysDepartPermission/queryById and read department permission records. The exposed fields include depart_id, permission_id, and data_rule_ids for any department.
How can I determine whether my deployment is affected?
Deployments of JeecgBoot through version 3.9.5 are affected according to the available information. As a controlled authenticated low-privilege user, test whether the queryById endpoint returns another department's permission record when given its ID.