Skip to content
Threat Feed
high advisory

Missing Authorization Vulnerability in JeecgBoot SysLogController

JeecgBoot versions 3.9.5 and earlier contain a missing authorization vulnerability in the SysLogController that allows low-privileged authenticated users to delete system audit logs via a specially crafted request.

CVE search metadata

CVE search record: CVE-2026-108623. Severity: high. CVSS: 7.1. KEV: no. Product: JeecgBoot (<= 3.9.5). Brief: Missing Authorization Vulnerability in JeecgBoot SysLogController. Brief link: https://feed.craftedsignal.io/briefs/2026-10-jeecgboot-missing-auth/

JeecgBoot through version 3.9.5 contains a missing authorization vulnerability in the SysLogController deleteBatch handler. This vulnerability allows an authenticated user, regardless of their privilege level, to delete system audit logs by sending a crafted DELETE request. By providing the parameter ids=allclear to the relevant endpoint, an attacker can trigger the removal of all entries within the sys_log database table. This action effectively wipes out system audit trails, hindering forensic investigations and security monitoring efforts. This flaw is rated with a CVSS v3.1 base score of 7.1, reflecting its potential impact on security logging integrity. The vulnerability persists in all versions up to and including 3.9.5, necessitating a patch to enforce proper access control checks within the SysLogController.

Impact

Successful exploitation results in the permanent deletion of system audit logs, which directly impacts an organization's ability to monitor user activity and perform incident response. By clearing the sys_log table, an attacker can hide evidence of other malicious activities, complicating post-incident forensic analysis. This vulnerability affects all environments running vulnerable versions of JeecgBoot that are exposed to low-privileged users.

Recommendation

  • Upgrade all JeecgBoot instances to a patched version that enforces authorization checks on the SysLogController deleteBatch handler.
  • Implement strict access controls for web application endpoints to ensure that delete operations are restricted to authorized administrative roles.
  • Review existing audit logs for suspicious activity involving the SysLogController, particularly patterns involving the deletion of large volumes of records in a single request.

Immediate actions

Patch JeecgBoot instances to a version beyond 3.9.5

IT Operations 72h

Mitigations

Restrict access to the SysLogController deleteBatch endpoint via application-level authorization

immediate IT Operations

CVE-2026-108623