Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to modify message templates via PUT /sys/message/sysMessageTemplate/edit. Attackers can obtain template ids from the unguarded list endpoint and overwrite system notification titles and content, delivering attacker-supplied text or links to other users.
Published: 2026-10-10
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Modification of system notification templates by unauthenticated but authenticated low‑privileged users.
Action: Apply patch
AI Analysis

Impact

JeecgBoot through 3.9.5 contains a missing authorization flaw that permits any authenticated user with minimal privileges to change message templates via the PUT /sys/message/sysMessageTemplate/edit endpoint. By exploiting this, an attacker can obtain template identifiers from an unprotected list endpoint and overwrite system notification titles and content, injecting attacker‑supplied text or malicious links that will be presented to other users. The vulnerability does not give code execution but facilitates phishing or misinformation campaigns within the application.

Affected Systems

The affected product is JeecgBoot, versions up to and including 3.9.5. The patch fixes the issue in later releases, so all instances of JeecgBoot running 3.9.5 or older are vulnerable.

Risk and Exploitability

The CVSS base score of 5.3 classifies the risk as moderate. No EPSS score is available, and the vulnerability is not listed in CISA KEV, implying limited known exploitation. The attack likely requires authentication but does not need elevated privileges, making it accessible to a wide range of users. An attacker can exploit the flaw by first retrieving a template ID from the list endpoint and then sending a crafted PUT request to alter the template, enabling the delivery of arbitrary content to other users.

Generated by OpenCVE AI on October 11, 2026 at 00:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor-provided patch or upgrade to JeecgBoot 3.9.6 or later.
  • Restrict the /sys/message/sysMessageTemplate/edit endpoint to users with appropriate authorization roles, ensuring that only privileged accounts can modify templates.
  • Implement monitoring or WAF rules to detect and block unauthorized attempts to edit message templates, and review logs for anomalous activity.

Generated by OpenCVE AI on October 11, 2026 at 00:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
Description JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to modify message templates via PUT /sys/message/sysMessageTemplate/edit. Attackers can obtain template ids from the unguarded list endpoint and overwrite system notification titles and content, delivering attacker-supplied text or links to other users.
Title JeecgBoot through 3.9.5 Missing Authorization via sysMessageTemplate Edit Endpoint
First Time appeared Jeecg
Jeecg jeecg Boot
Weaknesses CWE-862
CPEs cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:*
Vendors & Products Jeecg
Jeecg jeecg Boot
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Jeecg Jeecg Boot
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-10T21:49:17.265Z

Reserved: 2026-10-10T20:17:30.906Z

Link: CVE-2026-108618

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T22:16:36.150

Modified: 2026-10-10T22:16:36.150

Link: CVE-2026-108618

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T23:30:17Z

Weaknesses