Description
JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability that allows authenticated users to read other users' AI voice generation history via the userId parameter of GET /airag/voice/listByUser. Attackers who know another user's id can retrieve submitted text-to-speech input, voice settings, timestamps, and generated audio file names and paths stored in Redis.
Published: 2026-10-10
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Read other user’s AI voice generation history
Action: Apply Patch
AI Analysis

Impact

JeecgBoot through version 3.9.5 contains an insecure direct object reference flaw that allows any authenticated user to retrieve the voice generation history of any other user. By supplying the target user’s ID in the GET /airag/voice/listByUser endpoint, an attacker can obtain the text‑to‑speech inputs, voice configuration, timestamps, and the names and paths of the generated audio files stored in Redis. This vulnerability is a classic IDOR problem (CWE‑639) and can expose sensitive personal data and usage patterns.

Affected Systems

The affected product is JeecgBoot, a Java-based framework used for building applications. The vulnerability exists in all installations using versions up to and including 3.9.5. No specific sub‑components beyond the /airag/voice module are listed, and vendor‑provided version ranges were not supplied.

Risk and Exploitability

The CVSS score of 5.3 places this issue in the moderate severity range. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been publicly exploited at scale. The likely attack vector is authenticated, requiring the attacker to have a legitimate user account. Attackers can simply supply the victim’s user ID and trigger the endpoint, which no input validation is applied to, producing the sensitive data leak.

Generated by OpenCVE AI on October 10, 2026 at 23:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply vendor patch once released
  • Implement role‑based checks so that the userId parameter can only reference the authenticated user’s own data
  • Expose audit logs and monitor for unauthorized read attempts on the AirAG voice endpoint

Generated by OpenCVE AI on October 10, 2026 at 23:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
Description JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability that allows authenticated users to read other users' AI voice generation history via the userId parameter of GET /airag/voice/listByUser. Attackers who know another user's id can retrieve submitted text-to-speech input, voice settings, timestamps, and generated audio file names and paths stored in Redis.
Title JeecgBoot through 3.9.5 IDOR via /airag/voice/listByUser userId Parameter
First Time appeared Jeecg
Jeecg jeecg Boot
Weaknesses CWE-639
CPEs cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:*
Vendors & Products Jeecg
Jeecg jeecg Boot
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Jeecg Jeecg Boot
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-10T21:49:11.261Z

Reserved: 2026-10-10T20:17:06.670Z

Link: CVE-2026-108609

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T22:16:34.823

Modified: 2026-10-10T22:16:34.823

Link: CVE-2026-108609

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T23:30:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key