CVE-2026-9580: JeecgBoot selectDepart LoginController.selectDepart access control
A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepart of the file /sys/selectDepart. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. Upgrading to version 3.9.2 is sufficient to fix this issue. It is suggested to upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JeecgBootto a version that resolves this vulnerability.Fixed in 3.9.2 - Configuration
Upgrade JeecgBoot to 3.9.2 to fix improper access controls caused by LoginController.selectDepart (/sys/selectDepart).
JeecgBoot LoginController.selectDepart /sys/selectDepart access control = improper access controls fixed by upgrade to 3.9.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9580?
The severity of CVE-2026-9580 is high, with a CVSS score of 7.3.
How do I fix CVE-2026-9580?
To fix CVE-2026-9580, update JeecgBoot to version 3.9.2 or later where this vulnerability has been addressed.
What type of access control vulnerability is CVE-2026-9580?
CVE-2026-9580 involves improper access controls in the LoginController.selectDepart function.
Can CVE-2026-9580 be exploited remotely?
Yes, CVE-2026-9580 can be exploited remotely due to its improper access control mechanisms.
Which versions of JeecgBoot are affected by CVE-2026-9580?
CVE-2026-9580 affects JeecgBoot versions up to and including 3.9.1.