CVE-2026-108643: JeecgBoot through 3.9.5 Missing Authorization via /sys/category/deleteBatch
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to delete category dictionary entries via DELETE /sys/category/deleteBatch. Attackers can obtain node ids from the unguarded rootList and childList endpoints and submit them to recursively delete entire syscategory subtrees, breaking dependent forms and dictionary fields.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated user with low privileges can exploit it. The attack is network-accessible and does not require user interaction.
What information does an attacker need to delete category data?
The attacker needs category node IDs. They can obtain those IDs from the unguarded rootList and childList endpoints, then submit them to the deleteBatch endpoint.
How extensive can the deletion be?
Submitting a category node ID can recursively delete its entire sys_category subtree. This can break forms and dictionary fields that depend on the deleted category entries.
How can defenders check for exploitation?
Review category dictionary entries for unexpected missing subtrees and investigate delete activity targeting DELETE /sys/category/deleteBatch. Also review access to the rootList and childList endpoints for users who should not be administering category dictionaries.