CVE-2026-75479: JimuReport Unauthenticated Report Listing and Share Token Disclosure
JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to enumerate all reports and retrieve share tokens. Attackers can use disclosed share tokens to access protected report endpoints and retrieve full report definitions including embedded SQL statements and live query data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-75479?
CVE-2026-75479 has a severity rating of high with a score of 7.5.
How does CVE-2026-75479 affect JimuReport?
CVE-2026-75479 allows unauthenticated attackers to enumerate all reports and retrieve share tokens for JimuReport.
How do I fix CVE-2026-75479?
To fix CVE-2026-75479, implement authentication checks for the report folder template listing endpoint.
What type of vulnerability is CVE-2026-75479?
CVE-2026-75479 is an authentication bypass vulnerability.
What can attackers do with the information from CVE-2026-75479?
Attackers can use the disclosed share tokens to access protected report endpoints and retrieve full report data.