---
id: CVE-2026-108675
title: >-
  JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the
  SysAnnouncementController editIzTop handler that allows low-privileged
  authenticated users to change announcement pin status
summary: >-
  JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the
  SysAnnouncementController editIzTop handler that allows low-privileged
  authenticated users to change announcement pin status. Attackers can send POST
  or PUT re…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
published: '2026-10-10'
updated: '2026-10-10'
sourceUpdated: '2026-10-10T22:16:44.493'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-108675'
references:
  - url: >-
      https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/JeecgBoot/poc_announcement_edit_iztop_post.py
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/jeecgboot/JeecgBoot/blob/e3b9dc0aefe1943d9772b026f64ed671a7c82802/jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysAnnouncementController.java#L230-L244
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/jeecgboot-through-3.9.5-missing-authorization-via-sys-annountcement-editiztop
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-10-10T22:34:13.273Z'
---

## Overview

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysAnnouncementController editIzTop handler that allows low-privileged authenticated users to change announcement pin status. Attackers can send POST or PUT requests with any announcement id to pin or unpin system notices shown at the top for all users.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
