{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ajeecgjeecgboot/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:jeecg:jeecgboot:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-108623"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["JeecgBoot (\u003c= 3.9.5)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","authorization","jeecgboot"],"_cs_type":"advisory","_cs_vendors":["Jeecg"],"content_html":"\u003cp\u003eJeecgBoot through version 3.9.5 contains a missing authorization vulnerability in the SysLogController deleteBatch handler. This vulnerability allows an authenticated user, regardless of their privilege level, to delete system audit logs by sending a crafted DELETE request. By providing the parameter ids=allclear to the relevant endpoint, an attacker can trigger the removal of all entries within the sys_log database table. This action effectively wipes out system audit trails, hindering forensic investigations and security monitoring efforts. This flaw is rated with a CVSS v3.1 base score of 7.1, reflecting its potential impact on security logging integrity. The vulnerability persists in all versions up to and including 3.9.5, necessitating a patch to enforce proper access control checks within the SysLogController.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the permanent deletion of system audit logs, which directly impacts an organization's ability to monitor user activity and perform incident response. By clearing the sys_log table, an attacker can hide evidence of other malicious activities, complicating post-incident forensic analysis. This vulnerability affects all environments running vulnerable versions of JeecgBoot that are exposed to low-privileged users.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all JeecgBoot instances to a patched version that enforces authorization checks on the SysLogController deleteBatch handler.\u003c/li\u003e\n\u003cli\u003eImplement strict access controls for web application endpoints to ensure that delete operations are restricted to authorized administrative roles.\u003c/li\u003e\n\u003cli\u003eReview existing audit logs for suspicious activity involving the SysLogController, particularly patterns involving the deletion of large volumes of records in a single request.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T23:57:17Z","date_published":"2026-10-10T23:57:17Z","id":"https://feed.craftedsignal.io/briefs/2026-10-jeecgboot-missing-auth/","summary":"JeecgBoot versions 3.9.5 and earlier contain a missing authorization vulnerability in the SysLogController that allows low-privileged authenticated users to delete system audit logs via a specially crafted request.","title":"Missing Authorization Vulnerability in JeecgBoot SysLogController","url":"https://feed.craftedsignal.io/briefs/2026-10-jeecgboot-missing-auth/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:jeecg:jeecgboot:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}