Impact
JeecgBoot versions up to and including 3.9.5 contain a missing authorization check in the delete handler of the Airag Word Template controller. The flaw permits any authenticated user, regardless of privilege level, to issue a DELETE request to /airag/word/delete and permanently remove any word template from the shared library. An attacker who can authenticate to the application can therefore delete critical or desired templates, disrupting service availability for legitimate users and potentially causing data loss or operational instability.
Affected Systems
The impact is limited to installations of JeecgBoot up to version 3.9.5. This includes the jeecg-boot-module-airag component that exposes the /airag/word/delete endpoint. All users who can log in to the system—whether administrators, managers or standard employees—are potentially able to exploit the vulnerability, but only those who have at least basic authentication credentials.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified, but the absence of an authentication barrier means an attacker can easily craft the DELETE request once inside. Because the vulnerability is contained to a single endpoint and does not bypass authentication entirely, the scope is limited to the application layer; however the disruption of template resources may affect business workflows. The CVE is currently not listed in CISA KEV, but the missing authorization warrants prompt remediation to prevent accidental or targeted removal of shared assets.
OpenCVE Enrichment