Executive brief
JeecgBoot is a low-code development platform used to rapidly build enterprise applications. A security flaw in the login controller allows unauthorized users to bypass access controls. This could allow an attacker to manipulate departmental or tenant settings, potentially leading to unauthorized data access or disruption of organizational structures within the platform.
Technical details
An improper access control vulnerability exists in JeecgBoot versions up to 3.9.1 within the 'LoginController.selectDepart' function of the '/sys/selectDepart' component. The flaw allows for cross-department or cross-tenant context injection due to insufficient validation of access rights during the department selection process. A remote, unauthenticated attacker can exploit this vulnerability to manipulate session contexts or gain unauthorized access to departmental data. The exploit has been publicly disclosed. The issue is resolved in version 3.9.2, which introduces stricter tenant isolation and permission checks.
Affected products
- JeecgBoot JeecgBoot up to 3.9.1
Timeline
- 2026-05-26: advisory: CVE-2026-9580 published via VulDB/NVD
- 2026-04-30: patched: Version 3.9.2 released with security fixes