Description
A vulnerability has been found in JeecgBoot up to 3.9.1. This impacts an unknown function of the component SysAnnouncementController. Such manipulation leads to improper authorization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor confirmed the issue and will provide a fix in the upcoming release.
Problem types
Incorrect Privilege Assignment
Timeline
| 2026-04-09: | Advisory disclosed |
| 2026-04-09: | VulDB entry created |
| 2026-04-09: | VulDB entry last update |
Credits
XinX (VulDB User)
VulDB CNA Team
References
vuldb.com/vuln/356553 (VDB-356553 | JeecgBoot SysAnnouncementController improper authorization)
vuldb.com/vuln/356553/cti (VDB-356553 | CTI Indicators (IOB, IOC, TTP))
vuldb.com/submit/793656 (Submit #793656 | jeecgboot web 3.9.1 Improper Access Controls)
github.com/jeecgboot/JeecgBoot/issues/9508
github.com/jeecgboot/JeecgBoot/issues/9508
github.com/jeecgboot/JeecgBoot/