Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiOcrController deleteById handler that allows any authenticated user to delete OCR records. Low-privileged attackers can obtain record ids from the unguarded GET /airag/ocr/list endpoint and repeatedly delete every shared OCR prompt record stored in Redis.
Published: 2026-10-10
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Deletion of OCR Records
Action: Apply Patch
AI Analysis

Impact

JeecgBoot versions up to 3.9.5 allow any authenticated user to invoke the deleteById endpoint of the AiOcrController, which removes OCR prompt records without checking proper authorization. The effect is data destruction and potential loss of shared OCR prompts stored in Redis, undermining the availability and integrity of the application’s data.

Affected Systems

Vendors: JeecgBoot. Product: JeecgBoot. Affected versions include all releases through 3.9.5; later releases are presumed to contain a fix.

Risk and Exploitability

With a CVSS score of 5.3 the vulnerability is considered moderate risk. Because the exploitation requires only an authenticated session, a low‑privileged attacker can enumerate record identifiers via the unprotected GET /airag/ocr/list endpoint and subsequently delete each shared OCR prompt. The EPSS score is not provided, and the vulnerability is not listed in CISA’s KEV catalogue, indicating no publicly known exploits at this time.

Generated by OpenCVE AI on October 10, 2026 at 23:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade JeecgBoot to version 3.9.6 or later when the authorization check is added to deleteById.
  • If an immediate upgrade is not possible, restrict access to the /airag/ocr/deleteById endpoint and enforce role‑based access control using the existing authentication mechanism.
  • Disable or remove the shared OCR prompt feature from Redis until a secure version is deployed, or manually remove existing records to prevent automated deletion.

Generated by OpenCVE AI on October 10, 2026 at 23:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
Description JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiOcrController deleteById handler that allows any authenticated user to delete OCR records. Low-privileged attackers can obtain record ids from the unguarded GET /airag/ocr/list endpoint and repeatedly delete every shared OCR prompt record stored in Redis.
Title JeecgBoot through 3.9.5 Missing Authorization via /airag/ocr/deleteById
First Time appeared Jeecg
Jeecg jeecg Boot
Weaknesses CWE-862
CPEs cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:*
Vendors & Products Jeecg
Jeecg jeecg Boot
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Jeecg Jeecg Boot
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-10T21:49:09.330Z

Reserved: 2026-10-10T20:10:15.646Z

Link: CVE-2026-108606

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T22:16:34.380

Modified: 2026-10-10T22:16:34.380

Link: CVE-2026-108606

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T23:45:18Z

Weaknesses