CVE-2026-108649: JeecgBoot through 3.9.5 Missing Authorization via /sys/api/queryUserRolesById
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the queryUserRolesById handler of SystemApiController that lets authenticated users read any user's role codes. Low-privileged attackers can send a userId to GET /sys/api/queryUserRolesById to enumerate role assignments and identify administrator accounts.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
An attacker needs an authenticated JeecgBoot account, including a low-privileged account. They can send a GET request to /sys/api/queryUserRolesById with a target userId.
What information can be exposed?
The vulnerable handler can disclose role codes assigned to arbitrary users. This allows a low-privileged user to enumerate role assignments and identify accounts with administrator roles.
Is unauthenticated exploitation possible?
The available information describes exploitation by authenticated users only. It does not indicate that the endpoint is accessible without authentication.