---
id: CVE-2026-75479
title: >-
  JimuReport contains an authentication bypass vulnerability in the report
  folder template listing endpoint that allows unauthenticated attackers to
  enumerate all reports and retrieve share tokens
summary: >-
  JimuReport contains an authentication bypass vulnerability in the report
  folder template listing endpoint that allows unauthenticated attackers to
  enumerate all reports and retrieve share tokens. Attackers can use disclosed
  share tokens …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-306
vendor: jeecgboot
product: jimureport
affected:
  - jimureport <= 2.3.4
published: '2026-08-17'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T20:06:30.133'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-75479'
references:
  - url: 'https://github.com/jeecgboot/jimureport'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/jeecgboot/jimureport/issues/4695'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/jimureport-unauthenticated-report-listing-and-share-token-disclosure
    label: disclosure@vulncheck.com
  - url: 'https://github.com/jeecgboot/jimureport/issues/4695'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00465
epssPercentile: 0.37629
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-08-18T14:15:46.190732Z'
ingestedAt: '2026-09-24T15:45:56.702Z'
---

## Overview

JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to enumerate all reports and retrieve share tokens. Attackers can use disclosed share tokens to access protected report endpoints and retrieve full report definitions including embedded SQL statements and live query data.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
