Missing Authorization Vulnerability in JeecgBoot SysLogController
JeecgBoot versions 3.9.5 and earlier contain a missing authorization vulnerability in the SysLogController that allows low-privileged authenticated users to delete system audit logs via a specially crafted request.
CVE search metadata
CVE search record: CVE-2026-108623. Severity: high. CVSS: 7.1. KEV: no. Product: JeecgBoot (<= 3.9.5). Brief: Missing Authorization Vulnerability in JeecgBoot SysLogController. Brief link: https://feed.craftedsignal.io/briefs/2026-10-jeecgboot-missing-auth/
JeecgBoot through version 3.9.5 contains a missing authorization vulnerability in the SysLogController deleteBatch handler. This vulnerability allows an authenticated user, regardless of their privilege level, to delete system audit logs by sending a crafted DELETE request. By providing the parameter ids=allclear to the relevant endpoint, an attacker can trigger the removal of all entries within the sys_log database table. This action effectively wipes out system audit trails, hindering forensic investigations and security monitoring efforts. This flaw is rated with a CVSS v3.1 base score of 7.1, reflecting its potential impact on security logging integrity. The vulnerability persists in all versions up to and including 3.9.5, necessitating a patch to enforce proper access control checks within the SysLogController.
Impact
Successful exploitation results in the permanent deletion of system audit logs, which directly impacts an organization's ability to monitor user activity and perform incident response. By clearing the sys_log table, an attacker can hide evidence of other malicious activities, complicating post-incident forensic analysis. This vulnerability affects all environments running vulnerable versions of JeecgBoot that are exposed to low-privileged users.
Recommendation
- Upgrade all JeecgBoot instances to a patched version that enforces authorization checks on the SysLogController deleteBatch handler.
- Implement strict access controls for web application endpoints to ensure that delete operations are restricted to authorized administrative roles.
- Review existing audit logs for suspicious activity involving the SysLogController, particularly patterns involving the deletion of large volumes of records in a single request.
Immediate actions
Patch JeecgBoot instances to a version beyond 3.9.5
Mitigations
Restrict access to the SysLogController deleteBatch endpoint via application-level authorization
CVE-2026-108623