Common Vulnerabilities and Exposures (CVE)

CVE-2026-108665

Oct 10, 2026 21:49:49 UTC

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragPromptsController edit handler that allows any authenticated user to modify AI prompt templates. Low-privileged attackers can send PUT or POST requests to /a...

CVE-2026-108664

Oct 10, 2026 21:49:48 UTC

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragPromptsController queryById handler that allows low-privileged authenticated users to read any AI prompt template. Attackers can enumerate ids via the unguar...

CVE-2026-108663

Oct 10, 2026 21:49:48 UTC

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController deleteApply handler that allows any authenticated user to reject tenant administrator applications. Low-privileged attackers can send PUT requ...

CVE-2026-108662

Oct 10, 2026 21:49:47 UTC

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to remove users from tenant product packs via PUT /sys/tenant/deleteTenantPackUser. Attackers can supply arbitrary userId ...

CVE-2026-108661

Oct 10, 2026 21:49:46 UTC

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to transfer tenant ownership via POST /sys/tenant/changeOwenUserTenant. Low-privileged attackers can supply userId and tenantId parame...

CVE-2026-108660

Oct 10, 2026 21:49:46 UTC

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to modify tenant settings by calling PUT /sys/tenant/updateApplyStatus. Low-privileged attackers can supply any tenant id to overwrite...

CVE-2026-108659

Oct 10, 2026 21:49:45 UTC

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController listPackByTenantUserId handler that allows any authenticated user to query tenant product packs. Low-privileged attackers can supply arbitrary...

CVE-2026-108658

Oct 10, 2026 21:49:44 UTC

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController queryTenantAuthInfo handler that allows any authenticated user to read other tenants' records. Low-privileged attackers can iterate small inte...

CVE-2026-108657

Oct 10, 2026 21:49:43 UTC

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController passApply handler that allows any authenticated user to approve tenant administrator applications. Attackers can file a pending application vi...

CVE-2026-108656

Oct 10, 2026 21:49:43 UTC

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController GET /sys/tenant/getTenantPackApplyUsers endpoint that allows any authenticated user to read tenant administrator applications. Low-privileged ...

CVE-2026-108655

Oct 10, 2026 21:49:42 UTC

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the QuartzJobController queryById handler that allows low-privileged authenticated users to read scheduled job records. Attackers can request GET /sys/quartzJob/query...

CVE-2026-108654

Oct 10, 2026 21:49:41 UTC

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the OssFileController queryById handler that allows low-privileged authenticated users to read object storage file records. Attackers who know a record id can request...

CVE-2026-108653

Oct 10, 2026 21:49:41 UTC

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the queryPageList handler of OpenApiController that allows any authenticated user to list OpenAPI registry definitions. Low-privileged attackers can query GET /openap...

CVE-2026-108652

Oct 10, 2026 21:49:40 UTC

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SystemApiController updateAvatar handler that allows any authenticated user to change other users' avatars. Low-privileged attackers can send PUT requests with a ...

CVE-2026-108651

Oct 10, 2026 21:49:39 UTC

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the getRolesByUserId handler of SystemApiController that allows authenticated users to retrieve any user's role codes. Low-privileged attackers can supply arbitrary u...