CVE-2026-108867 | JeecgBoot up to 3.9.5 SystemApiController getUserRoleSetById userId improper authorization
A vulnerability classified as problematic was found in JeecgBoot up to 3.9.5. Impacted is the function getUserRoleSetById of the component SystemApiController. Such manipulation of the argument userId leads to improper authorization.
This vulnerability is documented as CVE-2026-108867. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More