Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-108628

HIGH NVD
CVSS Score 8.1
Severity HIGH
Published Oct 10, 2026
Vendor unknown

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the saveDeptRolePermission endpoint of SysDepartPermissionController that allows any authenticated user to modify department role permissions. Low-privileged attackers can submit roleId and permissionIds values to grant arbitrary menu or button permissions, escalating privileges or revoking other users' permissions.

References