Junglewise Threat Intelligence

CVE-2026-18631: Jeequan Jeepay authorization bypass in WebSecurityConfig

CVE-2026-18631 · Severity: medium · CVSS 6.3 · Published 2026-08-03

Executive brief

Jeepay is a payment system management platform used to process and administer payment transactions. An authorization bypass vulnerability allows authenticated low-privilege users to access administrative APIs they should not have permission to view, potentially exposing sensitive system logs, payment configurations, merchant data, and enabling unauthorized administrative operations.

Technical details

The vulnerability is an authorization bypass caused by missing method-level security enforcement in Spring Security configuration. The application declares @PreAuthorize annotations on controller methods (e.g., @PreAuthorize("hasAuthority('ENT_LOG_LIST')")) in SysLogController and other endpoints, but the WebSecurityConfig class does not enable @EnableMethodSecurity. This causes the web-layer rule anyRequest().authenticated() to be the only enforced check, allowing any authenticated user to access protected endpoints regardless of their assigned permissions. An authenticated low-privilege user can directly request protected APIs such as GET /api/sysLog and receive HTTP 200 with sensitive data. No authentication bypass is required; the attacker must be an authenticated system user, and the exploit is publicly available.

Affected products

  • Jeequan Jeepay up to 3.2.9

Timeline

  • 2026-08-03: disclosed: CVE-2026-18631 published
  • 2026-06-09: other: Vulnerability verified in local environment

References