Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysPositionController deleteBatch handler that allows any authenticated user to delete organizational positions. Low-privileged attackers can send comma-separated position ids, obtained from the unguarded list endpoint, to remove all sys_position rows and orphan user-position assignments.
Published: 2026-10-10
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized deletion of organizational positions by any authenticated user
Action: Immediate Patch
AI Analysis

Impact

This vulnerability arises from a missing authorization check in the SysPositionController deleteBatch endpoint. The flaw permits any authenticated user to submit batch deletion requests for organizational positions, using comma‑separated IDs obtained from an unprotected list endpoint. As a result, attackers can delete position records and orphan user‑position relationships, disrupting role assignments and compromising system integrity.

Affected Systems

JeecgBoot versions up to and including 3.9.5 are affected. The issue resides in the SysPositionController component of the JeecgBoot framework, which is used by deployments that expose the /sys/position/deleteBatch API endpoint.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. With no EPSS data available, the exploitation probability is uncertain, but the vulnerability is easy to exploit as it only requires authentication and no special privileges. The attack vector is through the application layer, targeting authenticated users. The vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation yet.

Generated by OpenCVE AI on October 11, 2026 at 00:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest JeecgBoot release that includes the authorization fix for the deleteBatch endpoint.
  • If an update is unavailable, modify the SysPositionController to enforce proper role‑based access control before executing deletions.
  • Restrict API access to the /sys/position/deleteBatch endpoint to users with administrative privileges and review existing position data for any unintended deletions.

Generated by OpenCVE AI on October 11, 2026 at 00:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
Description JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysPositionController deleteBatch handler that allows any authenticated user to delete organizational positions. Low-privileged attackers can send comma-separated position ids, obtained from the unguarded list endpoint, to remove all sys_position rows and orphan user-position assignments.
Title JeecgBoot through 3.9.5 Missing Authorization via /sys/position/deleteBatch
First Time appeared Jeecg
Jeecg jeecg Boot
Weaknesses CWE-862
CPEs cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:*
Vendors & Products Jeecg
Jeecg jeecg Boot
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Jeecg Jeecg Boot
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-10T21:49:18.596Z

Reserved: 2026-10-10T20:17:31.570Z

Link: CVE-2026-108620

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T22:16:36.447

Modified: 2026-10-10T22:16:36.447

Link: CVE-2026-108620

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T23:30:17Z

Weaknesses