Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to create message templates by calling POST /sys/message/sysMessageTemplate/add. Attackers holding only minimal roles can insert arbitrary notification templates with chosen codes and content into the shared sys_sms_template library used for system, e-mail, SMS and IM notifications.
Published: 2026-10-10
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Authorization Bypass – low‑privileged users can create arbitrary message templates
Action: Apply Patch
AI Analysis

Impact

JeecgBoot versions through 3.9.5 contain a missing authorization check that allows authenticated users with minimal privileges to create message templates via the POST /sys/message/sysMessageTemplate/add endpoint. By inserting templates with chosen codes and content, an attacker can populate the shared sys_sms_template library, potentially enabling unauthorized system, email, SMS, or instant message notifications.

Affected Systems

Users running JeecgBoot up to and including version 3.9.5 are at risk. The vulnerability was discovered in the SysMessageTemplateController within the system module and affects any deployment that has not yet applied the fix found in later releases.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited. Exploitation requires only an authenticated session and minimal role permissions; attackers can trigger the new templates by sending crafted POST requests to the exposed endpoint without additional privileges.

Generated by OpenCVE AI on October 11, 2026 at 00:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade JeecgBoot to version 3.9.6 or later where the authorization check has been added
  • If an upgrade is delayed, modify the application’s role permissions so that only authorized roles can access the sysMessageTemplate/add endpoint
  • Deploy a web application firewall or reverse proxy rule to block POST requests to /sys/message/sysMessageTemplate/add from accounts lacking the necessary role

Generated by OpenCVE AI on October 11, 2026 at 00:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
Description JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to create message templates by calling POST /sys/message/sysMessageTemplate/add. Attackers holding only minimal roles can insert arbitrary notification templates with chosen codes and content into the shared sys_sms_template library used for system, e-mail, SMS and IM notifications.
Title JeecgBoot through 3.9.5 Missing Authorization via sysMessageTemplate/add Endpoint
First Time appeared Jeecg
Jeecg jeecg Boot
Weaknesses CWE-862
CPEs cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:*
Vendors & Products Jeecg
Jeecg jeecg Boot
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Jeecg Jeecg Boot
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-10T21:49:16.574Z

Reserved: 2026-10-10T20:17:30.576Z

Link: CVE-2026-108617

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T22:16:36.000

Modified: 2026-10-10T22:16:36.000

Link: CVE-2026-108617

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T23:30:17Z

Weaknesses