Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysUserController getUserDetailByUserId handler that allows any authenticated user to read other users' details. Low-privileged attackers can supply arbitrary userId values to retrieve real names, usernames, emails, phone numbers, birthdays, employee numbers, department paths and posts.
Published: 2026-10-11
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized disclosure of user personal information via missing authorization
Action: Apply Patch
AI Analysis

Impact

JeecgBoot through version 3.9.5 contains a missing authorization flaw in the SysUserController getUserDetailByUserId endpoint that allows any authenticated user to retrieve detailed information about any other user. The flaw permits exposure of real names, usernames, email addresses, phone numbers, birthdays, employee numbers, department paths and posts to low‑privileged attackers. This weakness is classed as CWE‑862 and results in a breach of confidentiality for user data.

Affected Systems

The vulnerability affects all installations of JeecgBoot up to and including version 3.9.5. The impacted component is the SysUserController within the JeecgBoot console. No specific build or environment constraints are documented, so any deployment of the affected version is susceptible unless patched.

Risk and Exploitability

The CVSS score of 5.3 places the vulnerability in the medium range. Since there is no EPSS score available and it is not listed in CISA KEV, the likelihood of exploitation today is uncertain but an authenticated user can execute the request without additional privilege escalation. The attack vector is thus an authenticated web request to /sys/user/getUserDetailByUserId; the flaw does not require any elevated privileges beyond valid credentials, making it a realistic threat for any user with access to the system.

Generated by OpenCVE AI on October 11, 2026 at 15:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade JeecgBoot to the latest release that includes a fix for the missing authorization bug
  • Modify system configuration to grant read permissions on user details only to administrators or the user themselves
  • Verify that any custom modifications or plugins do not re‑introduce the missing authorization issue by testing the getUserDetailByUserId endpoint with various authenticated accounts

Generated by OpenCVE AI on October 11, 2026 at 15:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Description JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysUserController getUserDetailByUserId handler that allows any authenticated user to read other users' details. Low-privileged attackers can supply arbitrary userId values to retrieve real names, usernames, emails, phone numbers, birthdays, employee numbers, department paths and posts.
Title JeecgBoot through 3.9.5 Missing Authorization via /sys/user/getUserDetailByUserId
First Time appeared Jeecg
Jeecg jeecg Boot
Weaknesses CWE-862
CPEs cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:*
Vendors & Products Jeecg
Jeecg jeecg Boot
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Jeecg Jeecg Boot
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T14:33:48.063Z

Reserved: 2026-10-11T14:20:04.302Z

Link: CVE-2026-108891

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T15:16:56.203

Modified: 2026-10-11T15:16:56.203

Link: CVE-2026-108891

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T15:30:18Z

Weaknesses