CVE-2026-7602: JeecgBoot FillRuleUtil edit improper authorization
A vulnerability was found in JeecgBoot up to 3.9.1. Affected by this vulnerability is an unknown functionality of the file /sys/fillRule/edit of the component FillRuleUtil Component. The manipulation of the argument ruleClass results in improper authorization. The attack may be performed from remote. The exploit has been made public and could be used. You should upgrade the affected component. The vendor confirmed the issue and will provide a fix in the upcoming release.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7602?
The severity of CVE-2026-7602 is classified as Medium due to the potential for improper authorization in JeecgBoot.
How do I fix CVE-2026-7602?
To fix CVE-2026-7602, it is recommended to update JeecgBoot to a version later than 3.9.1 that addresses the authorization issues.
What components are affected by CVE-2026-7602?
CVE-2026-7602 affects the FillRuleUtil component specifically within the /sys/fillRule/edit functionality.
What type of vulnerability is CVE-2026-7602?
CVE-2026-7602 is an authorization vulnerability that allows manipulation of user permissions in JeecgBoot.
Who is impacted by CVE-2026-7602?
Organizations using JeecgBoot versions up to 3.9.1 are at risk due to CVE-2026-7602.