Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysPositionController edit handler that allows any authenticated user to modify organizational positions. Low-privileged attackers can obtain position ids from the unguarded list endpoint and send PUT or POST requests to /sys/position/edit to alter position names, codes, and ranks.
Published: 2026-10-10
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized modification of organizational positions
Action: Patch
AI Analysis

Impact

JeecgBoot through version 3.9.5 contains a missing authorization flaw in the SysPositionController edit handler that lets any authenticated user alter position details such as names, codes, and ranks. The vulnerability is identified as a lack of access control (CWE-862) and enables low‑privileged attackers to modify organizational role information, potentially leading to privilege escalation or data integrity violations. The CVSS score of 5.3 reflects a moderate impact on confidentiality, integrity, and availability. The vulnerability is only exploitable by users who can authenticate to the system and does not require additional privileges beyond those granted to the attacker. The upstream code does not provide a unique SEI or remote vector, so the attack path requires the attacker to know or discover a valid session cookie or authentication token.

Affected Systems

All installations of JeecgBoot version 3.9.5 or earlier are affected. The vulnerability resides in the SysPositionController component responsible for editing organizational positions. Users of older versions who have not applied the latest release are at risk.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, while the EPSS score is not available, so the probability of exploitation is unknown. The vulnerability is not currently listed in the CISA KEV catalog. Attackers need only authenticated access to the application; they can retrieve position identifiers from the unguarded list endpoint and then issue PUT or POST requests to /sys/position/edit. Given that the flaw is a missing authorization check, once an attacker can authenticate they can change any position record associated with the session. The exploitability is low to moderate because it requires active authentication and does not involve remote code execution or extensive exploitation steps.

Generated by OpenCVE AI on October 11, 2026 at 00:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update JeecgBoot to version 3.9.6 or later to receive the authorization fix.
  • Restrict access to the /sys/position/edit endpoint so that only users with administrative or explicitly granted roles can perform edits.
  • Audit position data for unauthorized changes and review user permissions to ensure only authorized accounts can modify organizational roles.

Generated by OpenCVE AI on October 11, 2026 at 00:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
Description JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysPositionController edit handler that allows any authenticated user to modify organizational positions. Low-privileged attackers can obtain position ids from the unguarded list endpoint and send PUT or POST requests to /sys/position/edit to alter position names, codes, and ranks.
Title JeecgBoot through 3.9.5 Missing Authorization via /sys/position/edit
First Time appeared Jeecg
Jeecg jeecg Boot
Weaknesses CWE-862
CPEs cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:*
Vendors & Products Jeecg
Jeecg jeecg Boot
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Jeecg Jeecg Boot
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-10T21:49:19.294Z

Reserved: 2026-10-10T20:17:31.899Z

Link: CVE-2026-108621

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T22:16:36.583

Modified: 2026-10-10T22:16:36.583

Link: CVE-2026-108621

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T23:30:17Z

Weaknesses