CVE-2026-108638 PUBLISHED

JeecgBoot through 3.9.5 Missing Authorization via /sys/user/deleteGroupUser

Assigner: VulnCheck
Reserved: 10.10.2026 Published: 10.10.2026 Updated: 10.10.2026

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to remove group memberships via the deleteGroupUser handler in SysUserController. Attackers can send DELETE requests with arbitrary groupId and userId values to remove any user from any administrator-maintained user group without ownership or tenant checks.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor jeecgboot
Product JeecgBoot
Versions Default: unaffected
  • affected from 0 to 3.9.5 (incl.)

Credits

  • Yaqi Chao finder

References

Problem Types

  • Missing Authorization CWE