LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-9580

Published
CVSS7.3
Severityhigh
WeaknessCWE-266
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Description

A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepart of the file /sys/selectDepart. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. Upgrading to version 3.9.2 is sufficient to fix this issue. It is suggested to upgrade the affected component.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-9580

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-9580.