CVE-2026-78970
Last modified
CVE-2026-78970 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. JeecgBoot 3.9.2 and earlier contains an authorization bypass vulnerability in the SystemApiController component. An authenticated attacker with any valid JWT token can access multiple API endpoints (including queryAllUser, queryUsersByUsernames, queryUserById, and queryUsersByIds) to retrieve sensitive information of all users, including real names, phone numbers, email addresses, employee numbers, and role definitions, due to missing fine-grained permission checks and incomplete data desensitization.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
JeecgBoot 3.9.2 and earlier contains an authorization bypass vulnerability in the SystemApiController component. An authenticated attacker with any valid JWT token can access multiple API endpoints (including queryAllUser, queryUsersByUsernames, queryUserById, and queryUsersByIds) to retrieve sensitive information of all users, including real names, phone numbers, email addresses, employee numbers, and role definitions, due to missing fine-grained permission checks and incomplete data desensitization.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| — | — | n/a |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-78970?
How severe is CVE-2026-78970?
How do I fix CVE-2026-78970?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-78965Uninitialized resource in ANGLE in Google Chrome prior to 15…4.3
- CVE-2026-78966Externally controlled reference in QUIC in Google Chrome pri…4.3
- CVE-2026-78967Missing authorization in BFCache in Google Chrome prior to 1…6.5
- CVE-2026-78968Missing authorization in Core in Google Chrome prior to 152.…6.5
- CVE-2026-78969Uninitialized resource in Video in Google Chrome prior to 15…6.5
- CVE-2026-7897Use after free in Mobile in Google Chrome on iOS prior to 14…7.5
- CVE-2026-78971In Halo <= 2.25.4, the plugin management feature allows user…4.6
- CVE-2026-78974UI misrepresentation in Linux Toolkit Theming in Google Chro…5.4
- CVE-2026-78975Incorrect authorization in DOM in Google Chrome prior to 152…6.5
- CVE-2026-78976Improper input validation in StorageAccessAPI in Google Chro…4.3
- CVE-2026-78977Uninitialized resource in GPU in Google Chrome on on Android…6.5
- CVE-2026-78978Out of bounds read in ANGLE in Google Chrome on on Windows p…8.8
Are you affected by CVE-2026-78970?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
