{"id":"CVE-2026-88620","title":"SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an improper authorization vulnerability in the /employee/queryAll endpoint","summary":"SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an improper authorization vulnerability in the /employee/queryAll endpoint. The endpoint does not enforce the required function-level permission or data-scope authorization, allow…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-862"],"published":"2026-09-15","updated":"2026-09-22","sourceUpdated":"2026-09-22T20:00:03.713","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-88620","references":[{"url":"https://github.com/1024-lab/smart-admin","label":"cve@mitre.org"},{"url":"https://github.com/returnwrong/returnwrong-security-advisories/blob/main/CVE-2026-88620.md","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"epss":0.00189,"epssPercentile":0.08811,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-22T15:07:50.565784Z"},"ingestedAt":"2026-09-15T15:39:12.905Z","slug":"CVE-2026-88620","body":"## Overview\n\nSmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an improper authorization vulnerability in the /employee/queryAll endpoint. The endpoint does not enforce the required function-level permission or data-scope authorization, allowing an authenticated low-privileged employee to retrieve employee records belonging to other departments and users\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":209176,"id":"CVE-2026-88620","ts":1790093218985,"field":"cvss","old":null,"new":"4.3"},{"seq":209175,"id":"CVE-2026-88620","ts":1790093218985,"field":"severity","old":"none","new":"medium"}]}