Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysMessageController delete handler that allows low-privileged authenticated users to delete message records. Attackers can send DELETE requests with arbitrary id values to remove any sys_sms row, erasing records of sent notifications without ownership checks.
Published: 2026-10-11
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Jeecg jeecg-boot
Jeecgboot
Jeecgboot jeecgboot
Vendors & Products Jeecg jeecg-boot
Jeecgboot
Jeecgboot jeecgboot

Sun, 11 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Description JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysMessageController delete handler that allows low-privileged authenticated users to delete message records. Attackers can send DELETE requests with arbitrary id values to remove any sys_sms row, erasing records of sent notifications without ownership checks.
Title JeecgBoot through 3.9.5 Missing Authorization via /sys/message/sysMessage/delete
First Time appeared Jeecg
Jeecg jeecg Boot
Weaknesses CWE-862
CPEs cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:*
Vendors & Products Jeecg
Jeecg jeecg Boot
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Jeecg Jeecg-boot Jeecg Boot
Jeecgboot Jeecgboot
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T14:33:45.370Z

Reserved: 2026-10-11T13:35:28.913Z

Link: CVE-2026-108885

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T15:16:55.670

Modified: 2026-10-11T15:16:55.670

Link: CVE-2026-108885

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T17:00:09Z

Weaknesses