Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 30 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | JeecgBoot through 3.9.2 contains a broken access control vulnerability that allows authenticated low-privilege users to perform full create, read, update, and delete operations on OpenAPI credentials by accessing the OpenApiAuthController and OpenApiPermissionController endpoints which lack Shiro authorization annotations. Attackers can exploit the unenforced access controls to list, add, edit, and delete all AK/SK credential pairs, with the list endpoint returning secret keys in plaintext, enabling credential theft and unauthorized invocation of the OpenAPI surface. | |
| Title | JeecgBoot 3.9.2 - Missing Authorization on OpenAPI Credential Management Endpoints Exposes Access/Secret Keys | |
| First Time appeared |
Jeecgboot
Jeecgboot jeecgboot |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:jeecgboot:jeecgboot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jeecgboot
Jeecgboot jeecgboot |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-30T17:13:00.548Z
Reserved: 2026-06-30T12:45:25.468Z
Link: CVE-2026-58377
No data.
No data.
No data.
OpenCVE Enrichment
No data.