CVE-2026-108871: JeecgBoot through 3.9.5 Missing Authorization via POST /sys/sysDepartRole/datarule
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the saveDatarule handler of SysDepartRoleController that lets low-privileged authenticated users modify department role data rules. Attackers can send crafted permissionId, roleId and dataRuleIds values to overwrite dataruleids, widening row-level data access or altering filtering for other department roles.