Executive brief
JeecgBoot, a low-code development platform, contains a security flaw in its OpenAPI endpoint. An attacker could potentially bypass authentication mechanisms to perform unauthorized actions. While the attack is difficult to execute and requires high complexity, it could lead to unauthorized data modification or system interference.
Technical details
A vulnerability classified as improper authentication (CWE-287) exists in JeecgBoot version 3.9.1. The flaw is located within the processing of the /openapi/call/ file in the OpenAPI Endpoint component. An attacker can exploit this remotely without prior authentication, though the attack complexity is rated as high and exploitability is considered difficult. Successful exploitation allows for unauthorized manipulation of the endpoint. As of the disclosure date, the vendor has not responded to reports of this issue.
Affected products
- JeecgBoot JeecgBoot 3.9.1
Timeline
- 2026-05-24: disclosed: Initial public disclosure via VulDB and NVD.