CVE-2026-108872 | JeecgBoot up to 3.9.5 EditUsers handler /sys/user/batchEditUsers user/department authorization
A vulnerability labeled as problematic has been found in JeecgBoot up to 3.9.5. Affected by this issue is the function batchEditUsers of the file /sys/user/batchEditUsers of the component EditUsers handler. Executing a manipulation of the argument user/department can lead to missing authorization.
This vulnerability is tracked as CVE-2026-108872. The attack can be launched remotely. No exploit exists.VulDB Recent EntriesRead More