JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the OssFileController queryById handler that allows low-privileged authenticated users to read object storage file records. Attackers who know a record id can request GET /sys/oss/file/queryById to obtain original file names and direct storage URLs of files uploaded by other users.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 11 Oct 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jeecg jeecg-boot
Jeecgboot Jeecgboot jeecgboot |
|
| Vendors & Products |
Jeecg jeecg-boot
Jeecgboot Jeecgboot jeecgboot |
Sat, 10 Oct 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the OssFileController queryById handler that allows low-privileged authenticated users to read object storage file records. Attackers who know a record id can request GET /sys/oss/file/queryById to obtain original file names and direct storage URLs of files uploaded by other users. | |
| Title | JeecgBoot through 3.9.5 Missing Authorization via /sys/oss/file/queryById | |
| First Time appeared |
Jeecg
Jeecg jeecg Boot |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jeecg
Jeecg jeecg Boot |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-10T21:49:41.973Z
Reserved: 2026-10-10T20:19:19.591Z
Link: CVE-2026-108654
No data.
Status : Received
Published: 2026-10-10T22:16:41.497
Modified: 2026-10-10T22:16:41.497
Link: CVE-2026-108654
No data.
OpenCVE Enrichment
Updated: 2026-10-11T02:15:16Z
Weaknesses