Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysLogController deleteBatch handler that allows any authenticated user to delete system audit log entries. Low-privileged attackers can send a DELETE request with ids set to allclear to wipe the entire sys_log table, erasing all users' audit trails.
Published: 2026-10-10
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Unauthorized deletion of audit logs
Action: Patch Immediately
AI Analysis

Impact

JeecgBoot implements a deleteBatch endpoint for system audit logs that performs no authorization checks. As a result, any user who has successfully authenticated to the application can send a DELETE request and remove log entries. Low‑privileged attackers can pass the parameter 'ids=allclear' to delete every row in the sys_log table, wiping the audit trail and making post‑incident investigation difficult. This weakness is a classic case of Missing Authorization (CWE‑862).

Affected Systems

Affected product is JeecgBoot, version 3.9.5 and earlier. The issue exists in the SysLogController component that handles system log deletion. The vendors are JeecgBoot; the exact version number for the fix is not provided, but any release beyond 3.9.5 that implements proper authorization should be used.

Risk and Exploitability

With a CVSS score of 7.1 the vulnerability is considered high severity. Because the exploitation requires only an authenticated session, users with low privileges can trigger the delete at will. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog, yet the potential for evidence tampering makes it a significant risk in regulated or forensic environments.

Generated by OpenCVE AI on October 10, 2026 at 23:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest JeecgBoot release that includes an authorization check for the deleteBatch endpoint.
  • If an upgrade is not possible, remove or disable the deleteBatch endpoint for lower‑privileged users via role‑based access control in the application configuration.
  • After implementing any changes, audit system logs for any unexpected log deletion activity and enforce retention policies to prevent loss of audit data.

Generated by OpenCVE AI on October 10, 2026 at 23:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
Description JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysLogController deleteBatch handler that allows any authenticated user to delete system audit log entries. Low-privileged attackers can send a DELETE request with ids set to allclear to wipe the entire sys_log table, erasing all users' audit trails.
Title JeecgBoot through 3.9.5 Missing Authorization via /sys/log/deleteBatch
First Time appeared Jeecg
Jeecg jeecg Boot
Weaknesses CWE-862
CPEs cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:*
Vendors & Products Jeecg
Jeecg jeecg Boot
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Jeecg Jeecg Boot
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-10T21:49:20.623Z

Reserved: 2026-10-10T20:17:44.672Z

Link: CVE-2026-108623

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T22:16:36.870

Modified: 2026-10-10T22:16:36.870

Link: CVE-2026-108623

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T23:30:17Z

Weaknesses