CVE-2026-108882: JeecgBoot through 3.9.5 Missing Authorization via /sys/position/removePositionUser
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysPositionController removeUserPosition handler that allows any authenticated user to remove position members. Low-privileged attackers can send DELETE requests with arbitrary userIds and positionId values to delete sysuserposition rows, detaching users from positions without logging.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated JeecgBoot user, including a low-privileged account, can exploit it. The attacker does not need user interaction and can target arbitrary userId and positionId values.
What access or request is required for exploitation?
An attacker needs valid authentication and the ability to send DELETE requests to the affected removeUserPosition handler. Exploitation consists of supplying chosen user and position identifiers to remove the corresponding sys_user_position association.
What is the operational impact of a successful attack?
Successful exploitation detaches users from positions by deleting sys_user_position rows. The described behavior occurs without logging, which can make unauthorized membership removals harder to detect through normal audit records.
How can defenders determine whether they may have been affected?
Review sys_user_position associations for unexpected missing user-to-position assignments, particularly for privileged or business-critical positions. Because the described removals are not logged, investigation may require comparing current assignments with backups, exports, or other independent records.