CVE-2026-108680: JeecgBoot through 3.9.5 Missing Authorization via /sys/api/sendTemplateAnnouncement
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to send template notifications by calling POST /sys/api/sendTemplateAnnouncement. Low-privileged attackers can supply forged sender, recipients, title, and template parameters to deliver messages appearing to come from admin or system accounts.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated JeecgBoot user, including a low-privileged account, can exploit the affected endpoint. No user interaction is required.
What access and request are required to exploit it?
An attacker needs valid authentication and network access to POST to /sys/api/sendTemplateAnnouncement. They can provide forged sender, recipient, title, and template parameters.
What is the practical impact?
An attacker can send template notifications that appear to originate from administrator or system accounts. The reported impact is limited to integrity; no confidentiality or availability impact is specified.
Which versions are identified as affected?
JeecgBoot through version 3.9.5 is identified as affected.