CVE-2026-108649 | JeecgBoot up to 3.9.5 User Role Query queryUserRolesById SystemApiController.queryUserRolesById userId improper authorization

SecurityVulns

A vulnerability was found in JeecgBoot up to 3.9.5. It has been declared as problematic. This impacts the function SystemApiController.queryUserRolesById of the file /sys/api/queryUserRolesById of the component User Role Query. The manipulation of the argument userId results in improper authorization.

This vulnerability is identified as CVE-2026-108649. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More