Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysCommentController exportXls handler that allows any authenticated user to export all comments. Low-privileged attackers can request /sys/comment/exportXls to download every sys_comment row, including comment text and user ids on records they cannot access.
Published: 2026-10-11
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Access to Sensitive Comments
Action: Apply Patch
AI Analysis

Impact

The reported vulnerability arises from a missing authorization check in the SysCommentController exportXls handler. It allows any authenticated user to invoke /sys/comment/exportXls and retrieve every row from the sys_comment table, exposing comment text and user identifiers that the user would normally not be permitted to view. This results in a confidentiality compromise of user data and could enable low‑privileged attackers to gather contextual information about system usage and other users.

Affected Systems

JeecgBoot installations running through version 3.9.5 are affected. The issue exists in all releases up to and including 3.9.5, and the fix is referenced in later versions of the framework.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate risk. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The attack vector is straightforward: an authenticated user can send an HTTP request to the /sys/comment/exportXls endpoint and download all comments. Because no additional authentication or integrity checks are performed, low‑privileged attackers can harvest sensitive data from records that are otherwise beyond their access level.

Generated by OpenCVE AI on October 11, 2026 at 15:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade JeecgBoot to version 3.9.6 or later, which includes a fix for the missing authorization check.
  • If an immediate upgrade is not feasible, enforce role‑based access control on the /sys/comment/exportXls endpoint so that only privileged users can invoke it.
  • As a temporary workaround, disable the exportXls endpoint or block it through network firewall rules until a patch can be applied.

Generated by OpenCVE AI on October 11, 2026 at 15:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Description JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysCommentController exportXls handler that allows any authenticated user to export all comments. Low-privileged attackers can request /sys/comment/exportXls to download every sys_comment row, including comment text and user ids on records they cannot access.
Title JeecgBoot through 3.9.5 Missing Authorization via /sys/comment/exportXls
First Time appeared Jeecg
Jeecg jeecg Boot
Weaknesses CWE-862
CPEs cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:*
Vendors & Products Jeecg
Jeecg jeecg Boot
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Jeecg Jeecg Boot
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T14:33:46.686Z

Reserved: 2026-10-11T13:35:29.582Z

Link: CVE-2026-108887

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T15:16:55.930

Modified: 2026-10-11T15:16:55.930

Link: CVE-2026-108887

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T15:30:18Z

Weaknesses