Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragExtDataController exportXls handler that allows any authenticated user to export AI evaluator data. Low-privileged attackers can request /airag/extData/exportXls to download every user's airag_ext_data evaluator definitions and test-tracking records as an Excel workbook.
Published: 2026-10-10
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Data Exposure
Action: Patch
AI Analysis

Impact

Missing authorization in the AiragExtDataController exportXls endpoint allows any authenticated user to export all AI evaluator data and test-tracking records as an Excel file. An attacker who can authenticate to the system can therefore gain access to potentially sensitive user data, resulting in a confidentiality breach.

Affected Systems

JeecgBoot releases through version 3.9.5 are affected. The vulnerability resides in the AiragExtDataController component of the JeecgBoot module, impacting any deployment that has that module installed and permits user authentication.

Risk and Exploitability

The CVSS score is 5.3, indicating a moderate impact. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only a valid authenticated session, which can be provided by even low‑privileged users. Once authenticated, the attacker can make a direct request to /airag/extData/exportXls and receive the entire dataset in a single operation. The attack is straightforward and does not require additional privileges beyond login.

Generated by OpenCVE AI on October 11, 2026 at 00:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest JeecgBoot release (≥ 3.9.6) which contains the fixed exportXls authorization check.
  • If an upgrade is not immediately possible, block or remove access to the /airag/extData/exportXls endpoint at the web‑server or firewall level so that authenticated users cannot reach it.
  • Configure role‑based access control so that only users with explicit export rights can invoke this endpoint, mitigating the impact of any remaining authorization gaps.

Generated by OpenCVE AI on October 11, 2026 at 00:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Jeecg jeecg-boot
Vendors & Products Jeecg jeecg-boot

Sat, 10 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
Description JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragExtDataController exportXls handler that allows any authenticated user to export AI evaluator data. Low-privileged attackers can request /airag/extData/exportXls to download every user's airag_ext_data evaluator definitions and test-tracking records as an Excel workbook.
Title JeecgBoot through 3.9.5 Missing Authorization via /airag/extData/exportXls
First Time appeared Jeecg
Jeecg jeecg Boot
Weaknesses CWE-862
CPEs cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:*
Vendors & Products Jeecg
Jeecg jeecg Boot
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Jeecg Jeecg-boot Jeecg Boot
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-10T21:49:14.578Z

Reserved: 2026-10-10T20:17:29.887Z

Link: CVE-2026-108614

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T22:16:35.560

Modified: 2026-10-10T22:16:35.560

Link: CVE-2026-108614

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T23:45:18Z

Weaknesses