JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to enumerate all reports and retrieve share tokens. Attackers can use disclosed share tokens to access protected report endpoints and retrieve full report definitions including embedded SQL statements and live query data.
History

Mon, 17 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to enumerate all reports and retrieve share tokens. Attackers can use disclosed share tokens to access protected report endpoints and retrieve full report definitions including embedded SQL statements and live query data.
Title JimuReport Unauthenticated Report Listing and Share Token Disclosure
First Time appeared Jeecg
Jeecg jimureport
Weaknesses CWE-306
CPEs cpe:2.3:a:jeecg:jimureport:*:*:*:*:*:*:*:*
Vendors & Products Jeecg
Jeecg jimureport
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-17T20:36:05.442Z

Reserved: 2026-08-17T19:59:23.460Z

Link: CVE-2026-75479

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T21:16:50.333

Modified: 2026-08-17T21:16:50.333

Link: CVE-2026-75479

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T21:30:03Z