CVE-2026-108679: JeecgBoot through 3.9.5 Missing Authorization via /sys/api/sendBusAnnouncement

Published Oct 10, 2026
·
Updated

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the sendBusAnnouncement handler of SystemApiController that allows any authenticated user to send announcements without the required permissions. Low-privileged attackers can POST crafted bodies to /sys/api/sendBusAnnouncement with forged sender, recipients, title and content to deliver spoofed admin or system messages for phishing.

Affected Software

1 affected component
JeecgBoot JeecgBoot<=3.9.5

Event History

Oct 10, 2026
CVE Published
via MITRE·09:49 PM
Data Sourced
via MITRE·09:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated JeecgBoot user, including a low-privileged account, can exploit it. The attacker does not need the permissions normally required to send announcements.

2

What access and request capabilities does an attacker need?

The attacker needs valid authentication and network access to the JeecgBoot endpoint. They can POST a crafted request body to /sys/api/sendBusAnnouncement containing forged sender, recipient, title, and content fields.

3

What is the likely impact of exploitation?

An attacker can send spoofed messages presented as administrator or system announcements. This can support phishing against recipients and compromise the integrity of the platform's announcement channel.

4

How can defenders determine whether they may be affected?

Deployments running JeecgBoot through version 3.9.5 should be considered affected based on the available information. Review requests to /sys/api/sendBusAnnouncement and announcement records for unexpected senders, recipients, titles, or content submitted by low-privileged accounts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203