Summary
CVE-2026-75479 is an authentication bypass (CWE-306, Missing Authentication for Critical Function) in JimuReport, an open-source Java reporting/BI tool from jeecgboot. The report folder template listing endpoint can be queried by unauthenticated attackers to enumerate all reports and harvest embedded share tokens, which can then be replayed against protected report endpoints to retrieve full report definitions, SQL statements, and live query results. The flaw affects JimuReport versions 0 through 2.3.4 and carries a HIGH severity rating.
Technical details
- Root cause: the endpoint
GET /jmreport/query/report/folder/templateis annotated@JimuNoLoginRequired, causing JimuReport’s token interceptor to skip authentication validation for it entirely. - Trigger condition: an attacker simply sends an unauthenticated HTTP request to the exposed endpoint on an internet-facing JimuReport instance.
- Attack vector: network, no authentication or user interaction required, low attack complexity.
- Impact: the response discloses report metadata and
shareViewUrlvalues containing share tokens. Those tokens can be reused against other share-accessible endpoints (e.g./jmreport/show,/jmreport/getCharData) to retrieve complete report definitions, including embedded SQL statements and live query data — resulting in high-confidentiality information disclosure without requiring credentials.
Affected software
- JimuReport (jeecgboot/jimureport), versions 0 through 2.3.4 (confirmed vulnerable at commit fdd1ad4).
Severity
- CVSS v3.1: 7.5 (HIGH) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v4.0: 8.7 (HIGH) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Mitigation and recommended actions
- Immediate: no patched JimuReport version has been published by the vendor as of this writing; monitor the vendor’s GitHub repository and issue tracker for a fix and upgrade as soon as one is released.
- Workarounds: restrict network exposure of JimuReport to trusted internal networks or VPNs rather than the public internet; place the application behind a reverse proxy or WAF that blocks unauthenticated requests to
/jmreport/query/report/folder/templateand other/jmreport/*share-related endpoints; rotate/invalidate any share tokens that may have been exposed; monitor access logs for enumeration attempts against the report folder template listing endpoint.

