CVE-2026-108643: JeecgBoot through 3.9.5 Missing Authorization via /sys/category/deleteBatch

Published Oct 10, 2026
·
Updated

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to delete category dictionary entries via DELETE /sys/category/deleteBatch. Attackers can obtain node ids from the unguarded rootList and childList endpoints and submit them to recursively delete entire syscategory subtrees, breaking dependent forms and dictionary fields.

Affected Software

1 affected component
JeecgBoot JeecgBoot<=3.9.5

Event History

Oct 10, 2026
CVE Published
via MITRE·09:49 PM
Data Sourced
via MITRE·09:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated user with low privileges can exploit it. The attack is network-accessible and does not require user interaction.

2

What information does an attacker need to delete category data?

The attacker needs category node IDs. They can obtain those IDs from the unguarded rootList and childList endpoints, then submit them to the deleteBatch endpoint.

3

How extensive can the deletion be?

Submitting a category node ID can recursively delete its entire sys_category subtree. This can break forms and dictionary fields that depend on the deleted category entries.

4

How can defenders check for exploitation?

Review category dictionary entries for unexpected missing subtrees and investigate delete activity targeting DELETE /sys/category/deleteBatch. Also review access to the rootList and childList endpoints for users who should not be administering category dictionaries.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203