Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-108641

MEDIUM NVD
CVSS Score 4.3
Severity MEDIUM
Published Oct 10, 2026
Vendor unknown

Description

JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability that allows authenticated users to read other users' in-application messages via the getOne handler of SysAnnouncementSendController. Attackers can obtain delivery record ids from the unguarded /sys/sysAnnouncementSend/list endpoint and supply them as the sendId parameter to retrieve message titles, bodies, senders and recipients.

References