CVE-2026-7602

MEDIUM

JeecgBoot FillRuleUtil edit improper authorization

Title source: cna
STIX 2.1

Description

A vulnerability was found in JeecgBoot up to 3.9.1. Affected by this vulnerability is an unknown functionality of the file /sys/fillRule/edit of the component FillRuleUtil Component. The manipulation of the argument ruleClass results in improper authorization. The attack may be performed from remote. The exploit has been made public and could be used. You should upgrade the affected component. The vendor confirmed the issue and will provide a fix in the upcoming release.

References (6)

Core 6
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-360559 | JeecgBoot FillRuleUtil edit improper authorization
https://vuldb.com/vuln/360559
Signature, Permissions Required signature permissions-required
VDB-360559 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/360559/cti
Third Party Advisory third-party-advisory
Submit #805706 | jeecgboot JeecgBoot <= v3.9.1 Remote Code Execution
https://vuldb.com/submit/805706

Scores

CVSS v3 6.3
EPSS 0.0005
EPSS Percentile 15.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-266 CWE-285
Status published
Products (2)
None/JeecgBoot 3.9.0
None/JeecgBoot 3.9.1
Published May 02, 2026
Tracked Since May 02, 2026