CVE-2026-108644: JeecgBoot through 3.9.5 Missing Authorization via /sys/category/delete
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysCategoryController delete handler that allows any authenticated user to delete category dictionary nodes. Low-privileged attackers can obtain node ids from the unguarded rootList and childList endpoints and delete entire syscategory subtrees, breaking dependent forms and dictionary fields.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated JeecgBoot user, including a low-privileged account, can exploit it. No administrative permission is required for the affected delete handler.
What does an attacker need to delete category nodes?
The attacker needs a valid authenticated session and category node IDs. The rootList and childList endpoints can be used to obtain those IDs.
What is the operational impact of exploitation?
An attacker can delete category dictionary nodes, including entire sys_category subtrees. This can break dependent forms and dictionary fields.