CVE-2026-58375highCWE-306

CVE-2026-58375: high-severity vulnerability in jeecgboot jimureport

JimuReport 2.5.0 - Unauthenticated Report Export via /jmreport/auto/export

Published · Updated

41Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 8.7epss 0.6%
exploitation probability
0.6%top 51% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
JimuReport through 2.5.0 exposes the POST /jmreport/auto/export endpoint without authentication: the handler is annotated @JimuNoLoginRequired, so JimuReportTokenInterceptor skips all authentication and authorization, and the export service streams the rendered report for any supplied report id without verifying the auto-export configuration flag. An unauthenticated remote attacker can enumerate Snowflake report identifiers and export the full contents of any report, including the data returned by the report configured SQL queries and any credentials embedded in its data sources.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
jeecgboot · jimureport
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — jeecgboot jimureport

In the same product, most dangerous first.