CVE-2026-108650 | JeecgBoot up to 3.9.5 getUserPermissionSet SystemApiController.getUserPermissionSet userId authorization
A vulnerability was found in JeecgBoot up to 3.9.5. It has been rated as problematic. Affected is the function SystemApiController.getUserPermissionSet of the file /sys/api/getUserPermissionSet. This manipulation of the argument userId causes missing authorization.
This vulnerability is tracked as CVE-2026-108650. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More