Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysPositionController removeUserPosition handler that allows any authenticated user to remove position members. Low-privileged attackers can send DELETE requests with arbitrary userIds and positionId values to delete sys_user_position rows, detaching users from positions without logging.
Published: 2026-10-11
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized privilege removal
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the SysPositionController removeUserPosition handler of JeecgBoot up to version 3.9.5. Any authenticated user can send a DELETE request to /sys/position/removePositionUser with arbitrary userIds and positionId values, which causes the application to delete rows in the sys_user_position table. This detaches users from their assigned positions without logging the action, potentially disrupting role‑based access for legitimate users.

Affected Systems

JeecgBoot versions 3.9.5 and earlier, as the flaw exists in the SysPositionController component of the JeecgBoot application.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is an authenticated web request; any authenticated user can exploit the flaw by sending a DELETE request with crafted userIds and positionId values. Successful exploitation leads to unauthorized removal of user roles, which can impact availability of privileged actions for the affected users.

Generated by OpenCVE AI on October 11, 2026 at 15:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a JeecgBoot version that contains the missing authorization fix, as released by the vendor.
  • Restrict access to the /sys/position/removePositionUser API to authorized administrators only by adjusting the application’s role permissions.
  • Enable auditing or logging for all removal operations to detect and investigate unauthorized removal attempts.

Generated by OpenCVE AI on October 11, 2026 at 15:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Description JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysPositionController removeUserPosition handler that allows any authenticated user to remove position members. Low-privileged attackers can send DELETE requests with arbitrary userIds and positionId values to delete sys_user_position rows, detaching users from positions without logging.
Title JeecgBoot through 3.9.5 Missing Authorization via /sys/position/removePositionUser
First Time appeared Jeecg
Jeecg jeecg Boot
Weaknesses CWE-862
CPEs cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:*
Vendors & Products Jeecg
Jeecg jeecg Boot
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Jeecg Jeecg Boot
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T14:33:43.256Z

Reserved: 2026-10-11T13:35:27.996Z

Link: CVE-2026-108882

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T15:16:55.263

Modified: 2026-10-11T15:16:55.263

Link: CVE-2026-108882

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T15:30:18Z

Weaknesses