Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysMessageTemplateController delete handler that allows any authenticated user to delete message templates. Low-privileged attackers can obtain template ids from the unguarded list endpoint and delete shipped notification templates, causing system notices and workflow reminders to fail.
Published: 2026-10-11
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Missing Authorization – deletion of message templates by any authenticated user
Action: Patch
AI Analysis

Impact

The vulnerability resides in the SysMessageTemplateController delete handler and represents a Missing Authorization flaw, allowing any authenticated user to delete system message templates. By leveraging the unprotected list endpoint, attackers can discover template identifiers and delete shipped notification templates, which can cause system notices and workflow reminders to fail. The affected component is part of the JeecgBoot platform.

Affected Systems

JeecgBoot, version 3.9.5 and below are impacted. The flaw was discovered in the SysMessageTemplateController of the Jeecg module system.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. EPSS information is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated session; an attacker with login credentials or access to a legitimate account can exploit the endpoint. Successful exploitation could lead to denial of notification services within the application, potentially disrupting business processes.

Generated by OpenCVE AI on October 11, 2026 at 15:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to JeecgBoot version 3.9.6 or later to apply the vendor fix
  • If upgrading is not immediately possible, disable the delete endpoint or add an authorization check to prevent unauthenticated deletion
  • Verify that all API endpoints enforce proper authentication and authorization controls

Generated by OpenCVE AI on October 11, 2026 at 15:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Description JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysMessageTemplateController delete handler that allows any authenticated user to delete message templates. Low-privileged attackers can obtain template ids from the unguarded list endpoint and delete shipped notification templates, causing system notices and workflow reminders to fail.
Title JeecgBoot through 3.9.5 Missing Authorization via sysMessageTemplate Delete Endpoint
First Time appeared Jeecg
Jeecg jeecg Boot
Weaknesses CWE-862
CPEs cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:*
Vendors & Products Jeecg
Jeecg jeecg Boot
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Jeecg Jeecg Boot
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T14:33:44.647Z

Reserved: 2026-10-11T13:35:28.621Z

Link: CVE-2026-108884

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T15:16:55.533

Modified: 2026-10-11T15:16:55.533

Link: CVE-2026-108884

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T15:30:18Z

Weaknesses