VulnerabilityDeferred
CVE-2026-9581
A vulnerability was identified in JeecgBoot up to 3.9.1.
LOW 2.1EPSS 0.21%
Does this matter?
Lower severity and a low EPSS score (0.21%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is an unknown function of the file /sys/comment/add. Such manipulation leads to improper access controls. The attack can be executed remotely. The exploit is publicly available and might be used. Upgrading to version 3.9.2 is sufficient to resolve this issue. Upgrading the affected component is recommended.
- CVSS 4.0
- 2.1 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.21% probability · 11th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-266, CWE-284
- Source
- cna@vuldb.com
References
- https://github.com/jeecgboot/JeecgBoot/
- https://github.com/jeecgboot/JeecgBoot/issues/9598
- https://github.com/jeecgboot/JeecgBoot/issues/9598#issuecomment-4385719753
- https://github.com/jeecgboot/JeecgBoot/releases/tag/v3.9.2
- https://vuldb.com/submit/817918
- https://vuldb.com/vuln/365637
- https://vuldb.com/vuln/365637/cti
- https://github.com/jeecgboot/JeecgBoot/issues/9598#issuecomment-4385719753
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.