---
id: CVE-2026-108624
title: >-
  JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the
  SysMessageController deleteBatch handler that allows low-privileged
  authenticated users to delete message records
summary: >-
  JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the
  SysMessageController deleteBatch handler that allows low-privileged
  authenticated users to delete message records. Attackers can obtain record ids
  from the ung…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-862
published: '2026-10-10'
updated: '2026-10-10'
sourceUpdated: '2026-10-10T22:16:37.020'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-108624'
references:
  - url: >-
      https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/JeecgBoot/poc_console_delete_routes.py
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/jeecgboot/JeecgBoot/blob/e3b9dc0aefe1943d9772b026f64ed671a7c82802/jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/message/controller/SysMessageController.java#L104-L109
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/jeecgboot-through-3.9.5-missing-authorization-via-sysmessage-deletebatch-endpoint
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-10-10T22:34:13.252Z'
---

## Overview

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysMessageController deleteBatch handler that allows low-privileged authenticated users to delete message records. Attackers can obtain record ids from the unguarded list endpoint and submit them to deleteBatch to remove any message push records, including pending queued messages.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
