CVE-2026-108677: JeecgBoot through 3.9.5 Missing Authorization via /sys/api/getUserByName
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in GET /sys/api/getUserByName that allows low-privileged authenticated users to retrieve any user's stored password value. Attackers can decrypt the AES-CBC protected response using the hard-coded key exposed by /sys/getEncryptedString to obtain administrators' password ciphertexts for offline guessing.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs a low-privileged authenticated JeecgBoot account. No user interaction is required, and the affected endpoint is reachable over the network.
What information can an attacker obtain?
The vulnerable endpoint can expose any user's stored password value, including administrator accounts. The response is AES-CBC protected, but the hard-coded key can be obtained from /sys/getEncryptedString, enabling offline password guessing against the recovered password ciphertexts.
How can I determine whether my deployment is affected?
JeecgBoot versions through 3.9.5 are identified as affected. A deployment is exposed if a low-privileged authenticated user can call GET /sys/api/getUserByName for another account and retrieve its stored password value.