Authentication Bypass in JimuReport
JimuReport versions 2.3.4 and earlier contain an authentication bypass vulnerability allowing unauthenticated actors to enumerate reports and exfiltrate sensitive data via leaked share tokens.
CVE search metadata
CVE search record: CVE-2026-75479. Severity: high. CVSS: 7.5. KEV: no. Product: jimureport (<= 2.3.4). Brief: Authentication Bypass in JimuReport. Brief link: https://feed.craftedsignal.io/briefs/2026-08-jimureport-auth-bypass/
JimuReport versions 2.3.4 and earlier are susceptible to an authentication bypass vulnerability located within the report folder template listing endpoint. This vulnerability enables unauthenticated remote attackers to enumerate report objects and retrieve associated share tokens. By obtaining these tokens, an attacker can bypass authorization controls on protected report endpoints to access full report definitions. This access is significant because report definitions within JimuReport often contain sensitive information, including hardcoded SQL statements, database connection logic, and live query results from connected backend data sources. The vulnerability is categorized under CWE-306 (Missing Authentication for Critical Function).
Attack Chain
- The attacker performs reconnaissance on the target JimuReport instance to locate the report template folder listing endpoint.
- The attacker sends an unauthenticated HTTP request to the vulnerable endpoint.
- The application fails to validate the user's authentication status and returns a listing of reports along with their corresponding share tokens.
- The attacker parses the response to extract the target share tokens.
- The attacker uses a retrieved share token to perform a subsequent request against protected report endpoints.
- The application validates the share token as a legitimate access mechanism for the requested report.
- The application returns the full report definition, exposing underlying database structures and query data to the attacker.
Impact
Successful exploitation allows for the unauthorized retrieval of sensitive business intelligence, including embedded SQL statements, database schema details, and live data retrieved by the reports. This leads to information disclosure which could facilitate further attacks against backend database infrastructure. There are no currently observed victim counts, but the vulnerability affects all deployments running version 2.3.4 or earlier.
Recommendation
- Update JimuReport to a patched version immediately as referenced in the JeecgBoot project issues.
- Audit access logs for anomalous, high-frequency requests to report template listing endpoints from unauthenticated sources.
- Monitor webserver logs for unauthorized attempts to access report endpoints using share tokens that were not previously distributed to authorized users.
Immediate actions
Update JimuReport to versions beyond 2.3.4.
Threat Hunt
Search for unauthenticated requests to /jimureport/template/list.
Data: webserver_logs
Detection coverage 1
Detect CVE-2026-75479 Exploitation - Unauthenticated Access to JimuReport
highDetects unauthenticated requests to JimuReport report template listing endpoints which are indicative of CVE-2026-75479 exploitation attempts.
Detection queries are available on the platform. Get full rules →