CVE-2026-108653: JeecgBoot through 3.9.5 Missing Authorization via GET /openapi/list
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the queryPageList handler of OpenApiController that allows any authenticated user to list OpenAPI registry definitions. Low-privileged attackers can query GET /openapi/list to read virtual paths, internal origin URLs, IP whitelists, and header and parameter templates intended for administrators.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated JeecgBoot user, including a low-privileged account, can query the affected endpoint. No user interaction is required.
What information could an attacker obtain?
The endpoint can expose OpenAPI registry definitions, including virtual paths, internal origin URLs, IP whitelists, and administrator-oriented header and parameter templates.
How can I determine whether my deployment is affected?
In an affected JeecgBoot deployment, authenticate with a low-privileged account and request GET /openapi/list. If the response returns OpenAPI registry definitions, the authorization control is missing for that account.