Junglewise Threat Intelligence

CVE-2026-8196: JeecgBoot authorization bypass in mLogin endpoint

CVE-2026-8196 · Severity: low · CVSS 3.7 · Published 2026-05-09

Technologies: JeecgBoot. Vendors: JeecgBoot.

Executive brief

JeecgBoot, a low-code development platform, contains a security flaw in its mobile login component. An attacker could potentially bypass security checks, such as CAPTCHA verification, to gain unauthorized access to the system. While the attack is complex to execute, a successful exploit could compromise user accounts and sensitive business data.

Technical details

An authorization bypass vulnerability exists in JeecgBoot 3.9.1 within the mLogin endpoint, specifically located in the LoginController.java file. The flaw (CWE-285/CWE-639) allows a remote attacker to bypass intended authorization checks, potentially including CAPTCHA verification as suggested by external references. The attack vector is network-based and requires no prior authentication, but it is classified as high complexity (AC:H) and difficult to exploit. A proof-of-concept exploit has been published. As of the advisory date, the vendor has not responded to disclosure attempts, and no official patch has been confirmed.

Affected products

  • JeecgBoot JeecgBoot 3.9.1

Timeline

  • 2026-05-09: disclosed: Vulnerability disclosed and exploit published.
  • 2026-05-09: advisory: NVD/VulDB advisory published.

References

Related threats