Executive brief
Jeepay is a payment system management platform used to process and administer payment transactions. An authorization bypass vulnerability allows authenticated low-privilege users to access administrative APIs they should not have permission to view, potentially exposing sensitive system logs, payment configurations, merchant data, and enabling unauthorized administrative operations.
Technical details
The vulnerability is an authorization bypass caused by missing method-level security enforcement in Spring Security configuration. The application declares @PreAuthorize annotations on controller methods (e.g., @PreAuthorize("hasAuthority('ENT_LOG_LIST')")) in SysLogController and other endpoints, but the WebSecurityConfig class does not enable @EnableMethodSecurity. This causes the web-layer rule anyRequest().authenticated() to be the only enforced check, allowing any authenticated user to access protected endpoints regardless of their assigned permissions. An authenticated low-privilege user can directly request protected APIs such as GET /api/sysLog and receive HTTP 200 with sensitive data. No authentication bypass is required; the attacker must be an authenticated system user, and the exploit is publicly available.
Affected products
- Jeequan Jeepay up to 3.2.9
Timeline
- 2026-08-03: disclosed: CVE-2026-18631 published
- 2026-06-09: other: Vulnerability verified in local environment