No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 30 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 30 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | JeecgBoot through 3.9.2 contains a broken access control vulnerability that allows authenticated low-privilege users to perform full create, read, update, and delete operations on OpenAPI credentials by accessing the OpenApiAuthController and OpenApiPermissionController endpoints which lack Shiro authorization annotations. Attackers can exploit the unenforced access controls to list, add, edit, and delete all AK/SK credential pairs, with the list endpoint returning secret keys in plaintext, enabling credential theft and unauthorized invocation of the OpenAPI surface. | |
| Title | JeecgBoot 3.9.2 - Missing Authorization on OpenAPI Credential Management Endpoints Exposes Access/Secret Keys | |
| First Time appeared |
Jeecgboot
Jeecgboot jeecgboot |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:jeecgboot:jeecgboot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jeecgboot
Jeecgboot jeecgboot |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-30T17:13:00.548Z
Reserved: 2026-06-30T12:45:25.468Z
Link: CVE-2026-58377
Updated: 2026-06-30T17:06:40.600Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-30T21:00:13Z