CVE-2026-8196General

LOWCVSS 2.9 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in JeecgBoot 3.9.1. The impacted element is an unknown function of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/LoginController.java of the component mLogin Endpoint. This manipulation causes authorization bypass. The attack is possible to be carried out remotely. The attack is considered to have high complexity. The exploitability is regarded as difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-10: 3Technical Details · 2026-05-10: 105-10
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-8196 A flaw has been found in JeecgBoot 3.9.1. The impacted element is an unknown function of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/s… https://www.cve.org/CVERecord?id=CVE-2026-8196

    Post summary

    A flaw in JeecgBoot 3.9.1 has been identified, but the post offers no additional technical or remediation details.

    00010152
    57.5K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-8196 A flaw has been found in JeecgBoot 3.9.1. The impacted element is an unknown function of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/s… https://www.cve.org/CVERecord?id=CVE-2026-8196 ----- Traducción: CVE-2026-8196 Se … http://infoflow.cloud`

    Post summary

    The tweet announces a flaw in JeecgBoot 3.9.1 (CVE-2026-8196) but provides only minimal details and no further actionable information.

    0000028
    76 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8196 Authorization Bypass in JeecgBoot 3.9.1 mLogin Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8196

    Post summary

    The post announces an authorization bypass vulnerability (CVE‑2026‑8196) in JeecgBoot 3.9.1’s mLogin endpoint but offers no PoC, exploit code, or patch information.

    0000042
    4.0K followersView on X

Explore more