CVE-2026-108640: JeecgBoot through 3.9.5 Missing Authorization via /sys/sysDepartRole/queryById
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysDepartRoleController queryById handler that lacks Shiro permission annotations. Low-privileged authenticated attackers can request GET /sys/sysDepartRole/queryById with any id to read department role names, codes, descriptions and audit fields.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated with a low-privileged account. They can send requests to the affected endpoint over the network; no user interaction is required.
What information can an attacker access?
The endpoint can disclose department role names, codes, descriptions, and audit fields. The attacker can request records using arbitrary id values.
Is this an authorization bypass that allows modification of roles?
The provided information describes unauthorized reading of department role data only. It does not indicate that the endpoint permits role creation, modification, or deletion.