CVE-2026-108675: JeecgBoot through 3.9.5 Missing Authorization via /sys/annountCement/editIzTop
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysAnnouncementController editIzTop handler that allows low-privileged authenticated users to change announcement pin status. Attackers can send POST or PUT requests with any announcement id to pin or unpin system notices shown at the top for all users.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated user with low privileges can exploit it. The attacker does not need administrative permissions, but must be able to send POST or PUT requests to the affected handler.
What can an attacker change?
An attacker can supply any announcement ID to pin or unpin that system notice. This changes whether announcements are displayed at the top for all users.
Are unauthenticated deployments affected?
The available information indicates that authentication is required. It does not indicate that an unauthenticated attacker can exploit the issue.
How can defenders check for exploitation?
Review POST and PUT requests to /sys/annountCement/editIzTop, especially requests made by low-privileged accounts for announcement IDs they should not be able to administer. Also investigate unexpected changes to announcement pin status.