CVE-2026-8196 is an authorization bypass vulnerability in JeecgBoot 3.9.1. According to the provided content, the issue affects an unknown function in LoginController.java within the path jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/, specifically in the mLogin endpoint. A remote attacker can manipulate requests to this endpoint in a way that bypasses intended authorization checks. The exact vulnerable function and code path are not specified in the available information.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python proof-of-concept exploit for a JeecgBoot authentication weakness identified in the code/comments as CVE-2026-8196. The repository contains 4 files: a Python exploit (exploit.py), README, license, and .gitignore. The only code file and clear entry point is exploit.py. The exploit’s purpose is to demonstrate that JeecgBoot’s standard login endpoint (/sys/login) enforces captcha, while an alternate endpoint (/sys/mLogin) accepts the same username/password pair without captcha validation. The script uses requests.Session with JSON POST requests and a custom User-Agent to interact with the target. It provides three main capabilities: (1) test the normal login flow for comparison, (2) authenticate through /sys/mLogin to demonstrate captcha bypass, and (3) optionally iterate through a password list to demonstrate brute-force feasibility when rate limiting or account lockout are absent. Structurally, the code defines a JeecgBootBruteForcePoC class with methods test_standard_login(), mlogin(), and brute_force(). The main() function sets a placeholder target URL, a username, runs the standard login test, then runs the bypass test against /sys/mLogin. The brute-force routine is present but commented out in main, indicating the repository is more than a detector: it contains working exploit logic for repeated authentication attempts. No external command execution, shell payload, persistence, or post-exploitation logic is present. The exploit is operational but basic: it directly performs HTTP authentication attempts and prints returned JSON, including successful login result data. Fingerprintable targets in the code are the placeholder base URL http://your-target:8080/jeecg-boot and the two application paths /sys/login and /sys/mLogin.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.