CVE-2026-108651 | JeecgBoot up to 3.9.5 Role Retrieval getRolesByUserId userId improper authorization

SecurityVulns

A vulnerability categorized as problematic has been discovered in JeecgBoot up to 3.9.5. Affected by this vulnerability is the function getRolesByUserId of the file /sys/api/getRolesByUserId of the component Role Retrieval Handler. Such manipulation of the argument userId leads to improper authorization.

This vulnerability is listed as CVE-2026-108651. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More