---
id: CVE-2026-108638
title: >-
  JeecgBoot through 3.9.5 contains a missing authorization vulnerability that
  allows low-privileged authenticated users to remove group memberships via the
  deleteGroupUser handler in SysUserController
summary: >-
  JeecgBoot through 3.9.5 contains a missing authorization vulnerability that
  allows low-privileged authenticated users to remove group memberships via the
  deleteGroupUser handler in SysUserController. Attackers can send DELETE
  requests wi…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
published: '2026-10-10'
updated: '2026-10-10'
sourceUpdated: '2026-10-10T22:16:39.013'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-108638'
references:
  - url: >-
      https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/JeecgBoot/poc_user_group_member_removal.py
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/jeecgboot/JeecgBoot/blob/e3b9dc0aefe1943d9772b026f64ed671a7c82802/jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysUserController.java#L829-L844
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/jeecgboot-through-3.9.5-missing-authorization-via-sys-user-deletegroupuser
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-10-10T22:34:13.260Z'
---

## Overview

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to remove group memberships via the deleteGroupUser handler in SysUserController. Attackers can send DELETE requests with arbitrary groupId and userId values to remove any user from any administrator-maintained user group without ownership or tenant checks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
