HackerFeeds
All CVEs

CVE-2026-108628

HIGH8.1

Published 2026-10-10 · Source disclosure@vulncheck.com

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the saveDeptRolePermission endpoint of SysDepartPermissionController that allows any authenticated user to modify department role permissions. Low-privileged attackers can submit roleId and permissionIds values to grant arbitrary menu or button permissions, escalating privileges or revoking other users' permissions.

CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CWE-862
View on NVD