VulnerabilityDeferred
CVE-2026-9579
A vulnerability was found in JeecgBoot up to 3.9.1.
LOW 2.1EPSS 0.21%
Does this matter?
Lower severity and a low EPSS score (0.21%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was found in JeecgBoot up to 3.9.1. Impacted is the function user.getUsername of the file /sys/user/login/setting/userEdit of the component SysUser. The manipulation of the argument userIdentity results in improper access controls. The attack may be launched remotely. The exploit has been made public and could be used. Upgrading to version 3.9.2 is recommended to address this issue. The affected component should be upgraded.
- CVSS 4.0
- 2.1 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.21% probability · 11th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-266, CWE-284
- Source
- cna@vuldb.com
References
- https://github.com/jeecgboot/JeecgBoot/
- https://github.com/jeecgboot/JeecgBoot/issues/9596
- https://github.com/jeecgboot/JeecgBoot/issues/9596#issuecomment-4385414813
- https://github.com/jeecgboot/JeecgBoot/releases/tag/v3.9.2
- https://vuldb.com/submit/817891
- https://vuldb.com/vuln/365635
- https://vuldb.com/vuln/365635/cti
- https://github.com/jeecgboot/JeecgBoot/issues/9596
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.