Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AigcWordTemplateController delete handler that allows any authenticated user to delete word templates. Low-privileged attackers can send DELETE requests to /airag/word/delete with an id parameter to permanently remove any template from the shared library.
Published: 2026-10-10
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized deletion of shared word templates
Action: Apply Patch
AI Analysis

Impact

JeecgBoot versions up to and including 3.9.5 contain a missing authorization check in the delete handler of the Airag Word Template controller. The flaw permits any authenticated user, regardless of privilege level, to issue a DELETE request to /airag/word/delete and permanently remove any word template from the shared library. An attacker who can authenticate to the application can therefore delete critical or desired templates, disrupting service availability for legitimate users and potentially causing data loss or operational instability.

Affected Systems

The impact is limited to installations of JeecgBoot up to version 3.9.5. This includes the jeecg-boot-module-airag component that exposes the /airag/word/delete endpoint. All users who can log in to the system—whether administrators, managers or standard employees—are potentially able to exploit the vulnerability, but only those who have at least basic authentication credentials.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified, but the absence of an authentication barrier means an attacker can easily craft the DELETE request once inside. Because the vulnerability is contained to a single endpoint and does not bypass authentication entirely, the scope is limited to the application layer; however the disruption of template resources may affect business workflows. The CVE is currently not listed in CISA KEV, but the missing authorization warrants prompt remediation to prevent accidental or targeted removal of shared assets.

Generated by OpenCVE AI on October 11, 2026 at 00:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade JeecgBoot to a version where the delete controller has been patched to enforce proper authorization checks.
  • If an immediate upgrade is not feasible, restrict access to the /airag/word/delete endpoint by allowing only users with administrator or equivalent roles to perform delete operations.
  • Implement application‑layer monitoring or logging of DELETE requests to /airag/word/delete to detect unauthorized use and investigate incidents promptly.

Generated by OpenCVE AI on October 11, 2026 at 00:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
Description JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AigcWordTemplateController delete handler that allows any authenticated user to delete word templates. Low-privileged attackers can send DELETE requests to /airag/word/delete with an id parameter to permanently remove any template from the shared library.
Title JeecgBoot through 3.9.5 Missing Authorization via /airag/word/delete Endpoint
First Time appeared Jeecg
Jeecg jeecg Boot
Weaknesses CWE-862
CPEs cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:*
Vendors & Products Jeecg
Jeecg jeecg Boot
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Jeecg Jeecg Boot
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-10T21:49:12.577Z

Reserved: 2026-10-10T20:17:29.019Z

Link: CVE-2026-108611

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T22:16:35.120

Modified: 2026-10-10T22:16:35.120

Link: CVE-2026-108611

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T00:30:16Z

Weaknesses