Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragAppController release handler that allows any authenticated user to publish or unpublish other users' AI applications. Low-privileged attackers can send POST requests to /airag/app/release to obtain share tokens exposing applications to anonymous chat access, or invalidate existing share links.
Published: 2026-10-10
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Patch
AI Analysis

Impact

A flaw in the AiragAppController release handler permits any authenticated user to publish or unpublish other users’ AI applications. By sending POST requests to /airag/app/release, an attacker can generate share tokens that expose applications to anonymous access or invalidate existing share links, effectively altering the availability and exposure of those applications.

Affected Systems

JeecgBoot products through version 3.9.5 are vulnerable. Any deployment using JeecgBoot 3.9.5 or earlier is affected.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate impact, and the EPSS score is not available, meaning the likelihood of exploitation is unknown but the vulnerability does not require high privileges. Because the flaw requires only an authenticated user, an attacker with a valid account can achieve the exploit. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on October 11, 2026 at 00:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade JeecgBoot to a release newer than 3.9.5 to apply the vendor fix.
  • Restrict access to the /airag/app/release endpoint to users with explicit authorization rights, enforcing proper role checks.
  • Verify that other application modules do not contain similar missing authorization checks and conduct a comprehensive audit of access controls.

Generated by OpenCVE AI on October 11, 2026 at 00:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
Description JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragAppController release handler that allows any authenticated user to publish or unpublish other users' AI applications. Low-privileged attackers can send POST requests to /airag/app/release to obtain share tokens exposing applications to anonymous chat access, or invalidate existing share links.
Title JeecgBoot through 3.9.5 Missing Authorization via /airag/app/release Endpoint
First Time appeared Jeecg
Jeecg jeecg Boot
Weaknesses CWE-862
CPEs cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:*
Vendors & Products Jeecg
Jeecg jeecg Boot
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Jeecg Jeecg Boot
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-10T21:49:13.901Z

Reserved: 2026-10-10T20:17:29.609Z

Link: CVE-2026-108613

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T22:16:35.410

Modified: 2026-10-10T22:16:35.410

Link: CVE-2026-108613

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T23:30:17Z

Weaknesses