CVE-2026-108639 | JeecgBoot up to 3.9.5 deletePhysic handler SysDictController.deletePhysic id authorization

SecurityVulns

A vulnerability classified as problematic has been found in JeecgBoot up to 3.9.5. This affects the function SysDictController.deletePhysic of the component deletePhysic handler. The manipulation of the argument ID leads to missing authorization.

This vulnerability is traded as CVE-2026-108639. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More