CVE-2026-75479 PUBLISHED

JimuReport Unauthenticated Report Listing and Share Token Disclosure

Assigner: VulnCheck
Reserved: 17.08.2026 Published: 17.08.2026 Updated: 17.08.2026

JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to enumerate all reports and retrieve share tokens. Attackers can use disclosed share tokens to access protected report endpoints and retrieve full report definitions including embedded SQL statements and live query data.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor jeecgboot
Product jimureport
Versions Default: unaffected
  • affected from 0 to 2.3.4 (incl.)

Credits

  • geo-chen reporter

References

Problem Types

  • Missing Authentication for Critical Function CWE