CVE-2026-9579: JeecgBoot SysUser userEdit user.getUsername access control
A vulnerability was found in JeecgBoot up to 3.9.1. Impacted is the function user.getUsername of the file /sys/user/login/setting/userEdit of the component SysUser. The manipulation of the argument userIdentity results in improper access controls. The attack may be launched remotely. The exploit has been made public and could be used. Upgrading to version 3.9.2 is recommended to address this issue. The affected component should be upgraded.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JeecgBoot SysUserto a version that resolves this vulnerability.Fixed in 3.9.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9579?
CVE-2026-9579 has a medium severity rating of 6.3.
How do I fix CVE-2026-9579?
To fix CVE-2026-9579, update JeecgBoot to version 3.9.2 or later, which addresses the access control vulnerability.
What component is affected by CVE-2026-9579?
CVE-2026-9579 affects the SysUser component, specifically the user.getUsername function.
Can CVE-2026-9579 be exploited remotely?
Yes, CVE-2026-9579 can be exploited remotely due to improper access controls.
What operation does the CVE-2026-9579 vulnerability allow?
The vulnerability allows unauthorized manipulation of the userIdentity argument, leading to an access control bypass.