JeecgBoot Up to Version 3.9.5 Vulnerable to Multiple Authentication Bypass Flaws
Security repository VulDB has disclosed three missing authentication flaws in JeecgBoot up to version 3.9.5, impacting tenant controllers, user role queries, and system announcement endpoints.
By The Global Wire Newsroom · Reported from vuldb.com
Link preview · horizonglobalnews.com
JeecgBoot Up to Version 3.9.5 Vulnerable to Multiple Authentication Bypass Flaws
Security repository VulDB has disclosed three missing authentication flaws in JeecgBoot up to version 3.9.5, impacting tenant controllers, user role queries, and system announcement endpoints.

On Oct. 10, 2026, cybersecurity vulnerability database VulDB disclosed three security vulnerabilities affecting JeecgBoot, a widely used open-source enterprise rapid application development platform built on Java and Spring Boot. The security flaws, cataloged under identifiers CVE-2026-108656, CVE-2026-108679, and CVE-2026-108678, expose critical system application programming interface endpoints and backend controller handlers to unauthenticated network access across all platform software releases up to and including version 3.9.5. According to technical details published by VulDB, the vulnerabilities stem from missing authentication checks within components responsible for multi-tenant administration, system-wide notification dispatching, and user role database querying. In each instance, remotely located network clients can interact directly with sensitive execution paths without providing valid user credentials, session state identifiers, or cryptographic authentication tokens.
Key facts
What happened
According to reports published by VulDB on Oct. 10, 2026, technical audits of the JeecgBoot enterprise platform uncovered three distinct access control vulnerabilities affecting versions up to 3.9.5. Each vulnerability represents a failure in the application's request filtering layer to properly demand and verify authentication credentials before executing backend logic.
The first issue, tracked under the standard security identifier CVE-2026-108656, targets the `SysTenantController` component. In modern enterprise application frameworks, tenant controllers oversee multi-tenant logical partitioning, handling business organization structures, sub-domain allocations, and tenant-level system configurations. Reporting from VulDB indicates that `SysTenantController` fails to enforce authentication requirements, enabling unauthenticated HTTP requests to reach tenant management functions.
The second vulnerability disclosed by VulDB, designated as CVE-2026-108679, impacts the `sendBusAnnouncement` handler component located within the file path and controller method `SystemApiController.sendBusAnnouncement`. The associated network path is mapped to the web application endpoint `/sys/api/sendBusAnnouncement`. VulDB categorized this defect as problematic. Under normal operational conditions, system bus announcements distribute administrative alerts and internal messages across an enterprise network. However, the identified manipulation allows unauthenticated web requests to trigger the handler without establishing an authenticated user session.
The third security defect, recorded by VulDB as CVE-2026-108678, involves the `queryUserRoles` function operating inside the UserRoles handler component at endpoint `/sys/api/queryUserRoles`. Also classified by VulDB as problematic, this issue centers on the processing of the `username` parameter. By supplying manipulated inputs to the `username` argument within request parameters sent to `/sys/api/queryUserRoles`, an unauthenticated actor can bypass authentication routines and invoke the underlying function to extract user role data.
Why it matters
The discovery of three authentication flaws within JeecgBoot holds substantial operational and security implications for organizations relying on the platform for their enterprise digital infrastructure. Rapid application development frameworks like JeecgBoot provide pre-built architecture for building custom enterprise resource planning systems, internal administrative portals, human resource tools, and client relationship management software. When core components of such frameworks contain access control defects, every customized application built on top of the framework inherits those security vulnerabilities.
Missing authentication controls represent a fundamental violation of security architecture rules. Within the framework established by the Open Web Application Security Project, broken access controls represent the single most prevalent category of web application vulnerability. The operational risks stemming from these specific disclosures include:
1. Operational Reconnaissance and Privilege Mapping: The vulnerability in `/sys/api/queryUserRoles` (CVE-2026-108678) grants unauthenticated actors the ability to query user role information simply by varying the `username` input parameter. In security context, access to user role mappings allows malicious entities to perform automated reconnaissance across an organization's user base. By discovering which usernames hold elevated administrative roles or specialized permissions, attackers can assemble targeted lists for spear-phishing campaigns, credential stuffing, or brute-force authentication attacks.
2. Communications Tampering and Phishing Risks: Unauthenticated execution of `/sys/api/sendBusAnnouncement` (CVE-2026-108679) grants unauthorized senders access to internal broadcast functions. In enterprise environments where system announcements inform users of critical updates, maintenance windows, or login URL changes, an unauthorized entity capable of broadcasting messages can execute internal phishing schemes or spread operational misinformation to logged-in employees.
3. Multi-Tenant Boundary Degradation: Multi-tenant applications depend strictly on administrative isolation to prevent data leaks between different enterprise clients or organizational divisions. The missing authentication checks in `SysTenantController` (CVE-2026-108656) threaten tenant segregation integrity, potentially allowing unauthorized actors to modify tenant settings or access cross-tenant controls.
The background
To understand the significance of the vulnerabilities disclosed by VulDB, it is necessary to examine the architectural structure of JeecgBoot and modern Java web application security frameworks.
JeecgBoot is an open-source enterprise rapid application development platform designed to streamline full-stack web application creation. Built upon a Java backend ecosystem utilizing Spring Boot, MyBatis-Plus, and security libraries like Apache Shiro or Spring Security, JeecgBoot integrates with a frontend UI built using Vue.js and Ant Design Vue. The platform is popular among software developers and enterprise IT departments because it offers automated code generation, built-in role-based access control (RBAC), multi-tenant SaaS capabilities, and pre-packaged administrative dashboards.
In a standard Spring Boot enterprise web application, incoming HTTP requests pass through a security filter chain before reaching specific controller methods. Controllers—such as `SysTenantController` or `SystemApiController`—use mapping annotations to bind backend Java methods to URI paths like `/sys/api/sendBusAnnouncement` or `/sys/api/queryUserRoles`. Framework security filters are designed to inspect request headers for valid authentication credentials, such as Bearer JSON Web Tokens (JWT) or session cookies. If the request lacks valid proof of identity, the filter chain normally rejects the connection with an HTTP 401 Unauthorized or HTTP 403 Forbidden status code.
Missing authentication vulnerabilities occur when routing configurations explicitly exclude specific API endpoints from security filters, when access control annotations are omitted from controller classes, or when logic conditions fail to validate session identity prior to executing business logic.
Vulnerability reporting standardizes these defects through the Common Vulnerabilities and Exposures system, managed by MITRE alongside authorized CVE Numbering Authorities. Cybersecurity platforms like VulDB document and index these vulnerabilities to provide software maintainers, enterprise administrators, and security analysts with structured data regarding exposed components, vulnerable version ranges, and technical execution vectors.
Reaction
Following the publication of the disclosures by VulDB on Oct. 10, 2026, enterprise IT operations teams and software maintainers using JeecgBoot are expected to undertake defensive actions. Although the initial reports from VulDB do not feature public statements from the JeecgBoot open-source development team, standard industry remediation workflows dictate several immediate steps for affected organizations.
System administrators operating JeecgBoot instances in production environments are expected to review their software deployment versions to confirm whether they fall within the affected range up to version 3.9.5. Security teams typically implement interim mitigations, such as configuring Web Application Firewalls (WAF) or API gateways to block unauthenticated external traffic directed at URI paths `/sys/api/sendBusAnnouncement` and `/sys/api/queryUserRoles`. Furthermore, development teams maintain responsibility for reviewing application routing tables and security filter chain definitions within their custom JeecgBoot codebases to ensure all controllers enforce mandatory token validation.
What we don't know yet
While the technical summaries published by VulDB identify the affected endpoints and software components, several critical aspects of the security situation remain unresolved:
What to watch
Stakeholders monitoring the security status of JeecgBoot should track several key indicators over the coming days and weeks:
This report is based on original security disclosure data published by cybersecurity vulnerability database VulDB.
How this story was produced
This report was written by The Global Wire newsroom from reporting first published by vuldb.com. We verify the core facts against the original report, write our own account, and add the background and consequences a short wire item leaves out. Drafting is AI-assisted inside an editor-supervised pipeline, and every story is checked for accuracy of attribution, structure and duplication before it appears — full detail in our AI and funding disclosure.
Spotted an error? Tell us at corrections@horizonglobalnews.com and read our corrections policy or editorial standards.







Reader comments
Loading comments…