Description
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragExtDataController delete handler that allows low-privileged authenticated users to delete AI evaluator records. Attackers can send DELETE requests to /airag/extData/delete with any id parameter to remove other users' AI evaluator or test-tracking records without owner or tenant checks.
Published: 2026-10-10
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Deletion of AI evaluator records
Action: Apply Patch
AI Analysis

Impact

JeecgBoot versions up to 3.9.5 expose a missing authorization flaw in the AiragExtDataController delete handler. The flaw allows users who are authenticated but do not have proper privileges to issue DELETE requests to /airag/extData/delete with any identifier and remove other users’ AI evaluator or test‑tracking records. The impact is the loss or tampering of data that belongs to other users, effectively degrading the integrity and availability of the system’s AI evaluation component but not directly exposing confidential data.

Affected Systems

The vulnerability affects JeecgBoot products released through version 3.9.5. The affected controller is AiragExtDataController in the JeecgBoot module Airag. Any installations deploying these versions without the fix are susceptible.

Risk and Exploitability

The CVSS score of 5.3 classifies the flaw as moderate severity. The EPSS score is not available, indicating insufficient data to gauge exploitation likelihood, and the vulnerability is not listed in the CISA KEV catalog. Attackers require only an authenticated session with low privileges, meaning the vulnerability can be exploited remotely via the web interface by any user who can log into the application.

Generated by OpenCVE AI on October 11, 2026 at 00:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to JeecgBoot 3.9.6 or later, where the delete endpoint has proper owner and tenant checks
  • If immediate upgrade is not possible, restrict the /airag/extData/delete endpoint to users with explicit delete permissions or block it via firewall rules
  • Configure the application to enforce role‑based access control so that only authorized administrators can delete AI evaluator records

Generated by OpenCVE AI on October 11, 2026 at 00:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
Description JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragExtDataController delete handler that allows low-privileged authenticated users to delete AI evaluator records. Attackers can send DELETE requests to /airag/extData/delete with any id parameter to remove other users' AI evaluator or test-tracking records without owner or tenant checks.
Title JeecgBoot through 3.9.5 Missing Authorization via /airag/extData/delete
First Time appeared Jeecg
Jeecg jeecg Boot
Weaknesses CWE-862
CPEs cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:*
Vendors & Products Jeecg
Jeecg jeecg Boot
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Jeecg Jeecg Boot
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-10T21:49:15.261Z

Reserved: 2026-10-10T20:17:30.174Z

Link: CVE-2026-108615

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T22:16:35.703

Modified: 2026-10-10T22:16:35.703

Link: CVE-2026-108615

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T23:30:17Z

Weaknesses