JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysPositionController removeUserPosition handler that allows any authenticated user to remove position members. Low-privileged attackers can send DELETE requests with arbitrary userIds and positionId values to delete sys_user_position rows, detaching users from positions without logging.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 11 Oct 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysPositionController removeUserPosition handler that allows any authenticated user to remove position members. Low-privileged attackers can send DELETE requests with arbitrary userIds and positionId values to delete sys_user_position rows, detaching users from positions without logging. | |
| Title | JeecgBoot through 3.9.5 Missing Authorization via /sys/position/removePositionUser | |
| First Time appeared |
Jeecg
Jeecg jeecg Boot |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jeecg
Jeecg jeecg Boot |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-11T14:33:43.256Z
Reserved: 2026-10-11T13:35:27.996Z
Link: CVE-2026-108882
No data.
Status : Received
Published: 2026-10-11T15:16:55.263
Modified: 2026-10-11T15:16:55.263
Link: CVE-2026-108882
No data.
OpenCVE Enrichment
Updated: 2026-10-11T15:30:18Z
Weaknesses