CVE-2026-108874 | JeecgBoot up to 3.9.5 Department Charge Person changeDepartChargePerson userId/departmentId/status missing authentication

SecurityVulns

A vulnerability labeled as problematic has been found in JeecgBoot up to 3.9.5. This issue affects some unknown processing of the file /sys/user/changeDepartChargePerson of the component Department Charge Person. The manipulation of the argument userId/departmentId/status results in missing authentication.

This vulnerability is identified as CVE-2026-108874. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More