Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AigcWordTemplateController deleteBatch handler that allows low-privileged authenticated users to delete word templates. Attackers can send a DELETE request to /airag/word/deleteBatch with comma-separated ids to permanently delete any templates in the shared library.
Published: 2026-10-10
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized deletion of word templates by low‑privileged users
Action: Apply Patch
AI Analysis

Impact

JeecgBoot up to version 3.9.5 contains a missing authorization flaw in the AigcWordTemplateController deleteBatch endpoint. Attackers who are authenticated, even with limited privileges, can issue a DELETE request to /airag/word/deleteBatch, passing comma‑separated template identifiers, to permanently remove any word templates from the shared library. This results in irreversible data loss or disruption of downstream processes that rely on those templates and represents an unauthorized destruction capability. The weakness is categorized as CWE‑862 (Missing Authorization).

Affected Systems

The vulnerability affects the JeecgBoot application, specifically all releases through 3.9.5. Users running any 3.9.5 or earlier build are susceptible to the flaw.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. EPSS is not available, and the flaw is not listed in the CISA KEV catalog, suggesting limited evidence of exploitation in the wild. Attackers must be authenticated, but the low‑privilege requirement lowers the sophistication barrier. The vulnerability can be exploited by sending a crafted HTTP DELETE request to the specified endpoint, and the threat exists once an authenticated session is established.

Generated by OpenCVE AI on October 10, 2026 at 23:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade JeecgBoot to a version newer than 3.9.5 that includes the authorization fix
  • Revoke or restrict the delete permission from low‑privileged user roles to prevent unauthorized template removal
  • Audit the AigcWordTemplateController to ensure proper authorization checks are enforced for all template‑management operations

Generated by OpenCVE AI on October 10, 2026 at 23:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
Description JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AigcWordTemplateController deleteBatch handler that allows low-privileged authenticated users to delete word templates. Attackers can send a DELETE request to /airag/word/deleteBatch with comma-separated ids to permanently delete any templates in the shared library.
Title JeecgBoot through 3.9.5 Missing Authorization via /airag/word/deleteBatch
First Time appeared Jeecg
Jeecg jeecg Boot
Weaknesses CWE-862
CPEs cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:*
Vendors & Products Jeecg
Jeecg jeecg Boot
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Jeecg Jeecg Boot
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-10T21:49:13.201Z

Reserved: 2026-10-10T20:17:29.304Z

Link: CVE-2026-108612

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T22:16:35.267

Modified: 2026-10-10T22:16:35.267

Link: CVE-2026-108612

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T23:30:17Z

Weaknesses