CVE-2026-108679: JeecgBoot through 3.9.5 Missing Authorization via /sys/api/sendBusAnnouncement
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the sendBusAnnouncement handler of SystemApiController that allows any authenticated user to send announcements without the required permissions. Low-privileged attackers can POST crafted bodies to /sys/api/sendBusAnnouncement with forged sender, recipients, title and content to deliver spoofed admin or system messages for phishing.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated JeecgBoot user, including a low-privileged account, can exploit it. The attacker does not need the permissions normally required to send announcements.
What access and request capabilities does an attacker need?
The attacker needs valid authentication and network access to the JeecgBoot endpoint. They can POST a crafted request body to /sys/api/sendBusAnnouncement containing forged sender, recipient, title, and content fields.
What is the likely impact of exploitation?
An attacker can send spoofed messages presented as administrator or system announcements. This can support phishing against recipients and compromise the integrity of the platform's announcement channel.
How can defenders determine whether they may be affected?
Deployments running JeecgBoot through version 3.9.5 should be considered affected based on the available information. Review requests to /sys/api/sendBusAnnouncement and announcement records for unexpected senders, recipients, titles, or content submitted by low-privileged accounts.