CVE-2026-108652 | JeecgBoot up to 3.9.5 Avatar Update updateAvatar user id improper authorization
A vulnerability identified as problematic has been detected in JeecgBoot up to 3.9.5. Affected by this issue is the function updateAvatar of the component Avatar Update. Performing a manipulation of the argument user id results in improper authorization.
This vulnerability is cataloged as CVE-2026-108652. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More