Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the PUT /sys/dict/editDictByLowAppId endpoint that allows any authenticated user to modify low-code application dictionaries. Attackers can supply a dictionary's low_app_id, obtained from GET /sys/dict/list, via the lowAppId parameter or X-Low-App-ID header to rename dictionaries and replace their items.
Published: 2026-10-11
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized modification of application dictionaries by any authenticated user
Action: Patch
AI Analysis

Impact

JeecgBoot through version 3.9.5 contains a missing authorization flaw in the PUT /sys/dict/editDictByLowAppId endpoint, allowing any authenticated user to rename application dictionaries and replace their items. This flaw falls under CWE‑862 and permits attackers to alter configuration data, potentially compromising the integrity of low‑code applications and their data. The impact is limited to modified dictionary contents; it does not provide arbitrary code execution or full system compromise.

Affected Systems

The vulnerability affects JeecgBoot versions up to and including 3.9.5. No specific build numbers are listed beyond the major version, so any installation of JeecgBoot 3.9.5 or earlier is at risk. Upgrading to a later release that implements proper authorization for the /sys/dict/editDictByLowAppId endpoint eliminates the issue.

Risk and Exploitability

The CVSS base score is 5.3, indicating moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. Attackers must first authenticate to the system, then retrieve a dictionary’s low_app_id via GET /sys/dict/list and supply it in the lowAppId parameter or X‑Low‑App‑ID header to the PUT endpoint. Because the attack requires valid authentication and only affects application configuration, the likelihood of exploitation is moderate to lower in environments with tight access controls.

Generated by OpenCVE AI on October 11, 2026 at 15:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy the most recent JeecgBoot release that fixes the authorization check for the /sys/dict/editDictByLowAppId endpoint.
  • If an upgrade is not immediately possible, configure your application to restrict or deny the PUT/sys/dict/editDictByLowAppId operation for all authenticated users, for example by enforcing role‑based access control or using firewall rules to block the endpoint.
  • Continuously monitor application logs for attempts to alter dictionaries using the low_app_id parameter or the X‑Low‑App‑ID header to detect and respond to potential abuse.

Generated by OpenCVE AI on October 11, 2026 at 15:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Description JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the PUT /sys/dict/editDictByLowAppId endpoint that allows any authenticated user to modify low-code application dictionaries. Attackers can supply a dictionary's low_app_id, obtained from GET /sys/dict/list, via the lowAppId parameter or X-Low-App-ID header to rename dictionaries and replace their items.
Title JeecgBoot through 3.9.5 Missing Authorization via /sys/dict/editDictByLowAppId
First Time appeared Jeecg
Jeecg jeecg Boot
Weaknesses CWE-862
CPEs cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:*
Vendors & Products Jeecg
Jeecg jeecg Boot
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Jeecg Jeecg Boot
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T14:33:41.868Z

Reserved: 2026-10-11T13:34:55.526Z

Link: CVE-2026-108880

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T15:16:55.000

Modified: 2026-10-11T15:16:55.000

Link: CVE-2026-108880

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T15:30:18Z

Weaknesses