Description
JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability that allows authenticated users to delete other users' AI video generation records by supplying arbitrary userId values to DELETE /airag/video/deleteVideoRecord. Attackers can obtain record ids from the unchecked GET /airag/video/listByUser endpoint and delete victims' Redis-stored video history entries one record per request.
Published: 2026-10-10
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Insecure Direct Object Reference allowing deletion of other users’ AI video records
Action: Apply Patch
AI Analysis

Impact

A DELETE /airag/video/deleteVideoRecord endpoint in JeecgBoot 3.9.5 lacks validation that the supplied userId matches the authenticated user, enabling an authenticated attacker to delete video generation records belonging to any user ID they specify. By retrieving record identifiers from the unfiltered GET /airag/video/listByUser endpoint, an attacker can systematically erase victims’ Redis‑stored video history entries, erasing user data without affecting other system components.

Affected Systems

All installations of JeecgBoot up through version 3.9.5 are susceptible, as the vulnerability resides in the jeecg-boot module that handles AI video generation. Any instance exposing the DELETE endpoint to authenticated users is at risk.

Risk and Exploitability

The CVSS score of 5.3 classifies this issue as moderate severity, and the EPSS score is not available; it is not listed in the CISA KEV catalog. Exploitation requires valid user credentials, meaning only attackers who have gained legitimate access to the system can perform the deletion. While the vulnerability does not allow arbitrary code execution or denial of service, repeated use could cause significant data loss for affected users.

Generated by OpenCVE AI on October 11, 2026 at 00:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade JeecgBoot to a release that fixes the deleteVideoRecord IDOR control
  • Restrict the DELETE /airag/video/deleteVideoRecord endpoint to privileged accounts or require additional authorization checks
  • Implement server‑side logic that verifies the userId in the request matches the currently authenticated user before deletion

Generated by OpenCVE AI on October 11, 2026 at 00:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
Description JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability that allows authenticated users to delete other users' AI video generation records by supplying arbitrary userId values to DELETE /airag/video/deleteVideoRecord. Attackers can obtain record ids from the unchecked GET /airag/video/listByUser endpoint and delete victims' Redis-stored video history entries one record per request.
Title JeecgBoot through 3.9.5 IDOR via deleteVideoRecord userId Parameter
First Time appeared Jeecg
Jeecg jeecg Boot
Weaknesses CWE-639
CPEs cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:*
Vendors & Products Jeecg
Jeecg jeecg Boot
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Jeecg Jeecg Boot
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-10T21:49:09.981Z

Reserved: 2026-10-10T20:17:05.878Z

Link: CVE-2026-108607

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T22:16:34.530

Modified: 2026-10-10T22:16:34.530

Link: CVE-2026-108607

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T00:30:16Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key