CVE-2026-108866: JeecgBoot through 3.9.5 Missing Authorization via /sys/api/queryUserAuths
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows authenticated users to read any account's permissions via the queryUserAuths handler. Low-privileged attackers can supply an arbitrary userId parameter to retrieve another user's complete permission set and identify administrator accounts.