SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-75479

HIGH · CVSS 7.5 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

JimuReport is vulnerable due to an authentication bypass in the report folder template listing endpoint, enabling unauthenticated attackers to enumerate reports and obtain share tokens. This exposure allows attackers to access protected report endpoints, potentially retrieving sensitive information such as SQL statements and live query data. Organizations using JimuReport should prioritize addressing this vulnerability to mitigate the risk of unauthorized data access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-75479
Severity
HIGH
CVSS
7.5
EPSS
0.36%

Original NVD Description

JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to enumerate all reports and retrieve share tokens. Attackers can use disclosed share tokens to access protected report endpoints and retrieve full report definitions including embedded SQL statements and live query data.