CVE-2026-108652: JeecgBoot through 3.9.5 Missing Authorization via /sys/api/updateAvatar
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SystemApiController updateAvatar handler that allows any authenticated user to change other users' avatars. Low-privileged attackers can send PUT requests with a target user id and an arbitrary value, such as an attacker-controlled image URL, to replace administrators' avatars.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need?
The attacker needs an authenticated JeecgBoot account. A low-privileged user can exploit the issue; administrative privileges are not required.
Which accounts can be modified through this flaw?
An authenticated attacker can change the avatars of other users, including administrators, by supplying a target user ID.
What activity should defenders look for when investigating possible exploitation?
Review PUT requests to /sys/api/updateAvatar, particularly requests where the authenticated user updates an avatar for a different target user ID or supplies an unexpected image URL.