CVE-2026-9581: JeecgBoot add access control
A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is an unknown function of the file /sys/comment/add. Such manipulation leads to improper access controls. The attack can be executed remotely. The exploit is publicly available and might be used. Upgrading to version 3.9.2 is sufficient to resolve this issue. Upgrading the affected component is recommended.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JeecgBootto a version that resolves this vulnerability.Fixed in 3.9.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9581?
The severity of CVE-2026-9581 is rated as medium, with a score of 6.3.
How do I fix CVE-2026-9581?
To fix CVE-2026-9581, upgrade JeecgBoot to version 3.9.2 or later.
What kind of access control issue is present in CVE-2026-9581?
CVE-2026-9581 involves improper access controls that can be exploited remotely.
What versions of JeecgBoot are affected by CVE-2026-9581?
JeecgBoot versions up to and including 3.9.1 are affected by CVE-2026-9581.
Is the exploit for CVE-2026-9581 publicly available?
Yes, the exploit for CVE-2026-9581 is publicly available and could be used by attackers.