Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiOcrController updateById handler that allows any authenticated user to modify global OCR templates. Low-privileged attackers can send PUT requests to /airag/ocr/edit to overwrite LLM prompts in the shared airag:ocr Redis key, corrupting OCR results for all users.
Published: 2026-10-10
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized modification of OCR templates by authenticated users
Action: Patch and Restrict
AI Analysis

Impact

JeecgBoot versions through 3.9.5 contain a missing authorization flaw in the AiOcrController updateById handler that lets any authenticated user send a PUT request to the /airag/ocr/edit endpoint to overwrite the shared LLM prompt stored in the airag:ocr Redis key. This can corrupt OCR results for all users, effectively allowing an attacker to tamper with application data and user experience. The weakness is a direct lack of permission checks for a protected resource, classified as CWE-862.

Affected Systems

The vulnerability affects the JeecgBoot application component known as JeecgBoot, specifically all releases up to and including 3.9.5. No other products or vendors are known to be impacted.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity. Because the EPSS score is not available and the vulnerability is not listed in CISA KEV, there is no published exploitation data. Attackers must be authenticated, but no higher privileges are required. The data can be modified by any user with basic access, providing a low-privileged vector for unauthorized changes.

Generated by OpenCVE AI on October 10, 2026 at 23:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade JeecgBoot to version 3.9.6 or later where the /airag/ocr/edit endpoint requires proper authorization.
  • If an upgrade is not feasible, configure application or network controls to restrict the /airag/ocr/edit path to privileged roles or service accounts only.
  • Implement application‑level input validation or role checks so that only users with explicit OCR‑template‑management rights can forward PUT requests to the edit endpoint.
  • Monitor changes to the airag:ocr Redis key for unauthorized modifications and alert on anomalies.

Generated by OpenCVE AI on October 10, 2026 at 23:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
Description JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiOcrController updateById handler that allows any authenticated user to modify global OCR templates. Low-privileged attackers can send PUT requests to /airag/ocr/edit to overwrite LLM prompts in the shared airag:ocr Redis key, corrupting OCR results for all users.
Title JeecgBoot through 3.9.5 Missing Authorization via /airag/ocr/edit Endpoint
First Time appeared Jeecg
Jeecg jeecg Boot
Weaknesses CWE-862
CPEs cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:*
Vendors & Products Jeecg
Jeecg jeecg Boot
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Jeecg Jeecg Boot
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-10T21:49:08.668Z

Reserved: 2026-10-10T20:10:12.378Z

Link: CVE-2026-108605

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T22:16:34.213

Modified: 2026-10-10T22:16:34.213

Link: CVE-2026-108605

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T23:45:18Z

Weaknesses