CVE-2026-108637 | JeecgBoot up to 3.9.5 User Group Member Removal deleteUserGroupBatch groupId/userIds improper authorization
A vulnerability described as problematic has been identified in JeecgBoot up to 3.9.5. Affected by this issue is some unknown functionality of the file /sys/user/deleteUserGroupBatch of the component User Group Member Removal. Executing a manipulation of the argument groupId/userIds can lead to improper authorization.
This vulnerability appears as CVE-2026-108637. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More