CVE-2026-9580 PUBLISHED

JeecgBoot selectDepart LoginController.selectDepart access control

Assigner: VulDB
Reserved: 26.05.2026 Published: 26.05.2026 Updated: 27.05.2026

A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepart of the file /sys/selectDepart. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. Upgrading to version 3.9.2 is sufficient to fix this issue. It is suggested to upgrade the affected component.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 6.9

Product Status

Vendor n/a
Product JeecgBoot
Versions
  • Version 3.9.0 is affected
  • Version 3.9.1 is affected
  • Version 3.9.2 is unaffected

Credits

  • AliceS614 (VulDB User) reporter

References

Problem Types

  • Improper Access Controls CWE
  • Incorrect Privilege Assignment CWE