Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-108648

MEDIUM NVD
CVSS Score 6.5
Severity MEDIUM
Published Oct 10, 2026
Vendor unknown

Description

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the GET /sys/api/getDynamicDbSourceByCode endpoint of SystemApiController, which lacks Shiro permission or role annotations. Any authenticated low-privileged user can supply datasource codes in the dbSourceCode parameter to retrieve JDBC URLs, usernames and decrypted cleartext database passwords.

References