CVE-2026-108627 | JeecgBoot up to 3.9.5 loadDatarule handler /sys/role/datarule SysRoleController.loadDatarule permissionId/roleId authorization
A vulnerability was found in JeecgBoot up to 3.9.5. It has been classified as problematic. Impacted is the function SysRoleController.loadDatarule of the file /sys/role/datarule of the component loadDatarule handler. Performing a manipulation of the argument permissionId/roleId results in missing authorization.
This vulnerability is identified as CVE-2026-108627. The attack can be initiated remotely. There is not any exploit available.VulDB Recent EntriesRead More