JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the loadDatarule handler of SysRoleController that lets any authenticated user query role data rules. Low-privileged attackers can request GET /sys/role/datarule/{permissionId}/{roleId} to read rule names, columns, conditions, values and bound rule ids for any role.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 10 Oct 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the loadDatarule handler of SysRoleController that lets any authenticated user query role data rules. Low-privileged attackers can request GET /sys/role/datarule/{permissionId}/{roleId} to read rule names, columns, conditions, values and bound rule ids for any role. | |
| Title | JeecgBoot through 3.9.5 Missing Authorization via /sys/role/datarule Endpoint | |
| First Time appeared |
Jeecg
Jeecg jeecg Boot |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jeecg
Jeecg jeecg Boot |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-10T21:49:23.277Z
Reserved: 2026-10-10T20:18:18.686Z
Link: CVE-2026-108627
No data.
Status : Received
Published: 2026-10-10T22:16:37.450
Modified: 2026-10-10T22:16:37.450
Link: CVE-2026-108627
No data.
OpenCVE Enrichment
No data.
Weaknesses