Common Vulnerabilities and Exposures (CVE)

CVE-2026-108680

Oct 10, 2026 21:49:59 UTC

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to send template notifications by calling POST /sys/api/sendTemplateAnnouncement. Low-privileged attackers can supply forged sender, r...

CVE-2026-108679

Oct 10, 2026 21:49:58 UTC

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the sendBusAnnouncement handler of SystemApiController that allows any authenticated user to send announcements without the required permissions. Low-privileged attac...

CVE-2026-108678

Oct 10, 2026 21:49:57 UTC

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the queryUserRoles handler of SystemApiController that lets authenticated users read any user's role codes. Low-privileged attackers can send GET requests to /sys/api...

CVE-2026-108677

Oct 10, 2026 21:49:57 UTC

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in GET /sys/api/getUserByName that allows low-privileged authenticated users to retrieve any user's stored password value. Attackers can decrypt the AES-CBC protected re...

CVE-2026-108676

Oct 10, 2026 21:49:56 UTC

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysAnnouncementController downLoadFiles handler that allows low-privileged authenticated users to download announcement attachments. Attackers can supply a known ...

CVE-2026-108675

Oct 10, 2026 21:49:55 UTC

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysAnnouncementController editIzTop handler that allows low-privileged authenticated users to change announcement pin status. Attackers can send POST or PUT reque...

CVE-2026-108674

Oct 10, 2026 21:49:55 UTC

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the OpenApiController queryById handler that allows low-privileged authenticated users to read OpenAPI definitions without openapi permissions. Attackers can request ...

CVE-2026-108673

Oct 10, 2026 21:49:54 UTC

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragPromptsController exportXls handler that allows any authenticated user to export all AI prompts. Low-privileged attackers can request /airag/prompts/exportXl...

CVE-2026-108672

Oct 10, 2026 21:49:53 UTC

JeecgBoot through 3.9.5 contains an authorization bypass vulnerability in the getVideoRecords handler of VideoGenerationController that allows authenticated users to read other users' records via the userId parameter. Low-privileged attacke...

CVE-2026-108671

Oct 10, 2026 21:49:53 UTC

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to read MCP server configurations because the queryById permission check is commented out. Attackers can obtain record ids from the un...

CVE-2026-108670

Oct 10, 2026 21:49:52 UTC

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the promptExperiment handler of AiragPromptsController that allows any authenticated user to run AI prompt experiments. Low-privileged attackers can supply other user...

CVE-2026-108669

Oct 10, 2026 21:49:52 UTC

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the embeddingSearch handler of AiragKnowledgeController that lacks Shiro permission annotations. Low-privileged authenticated attackers can supply knowledge base ids ...

CVE-2026-108668

Oct 10, 2026 21:49:51 UTC

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragPromptsController deleteRecycleBin handler that allows any authenticated user to purge AI prompt templates. Low-privileged attackers can send DELETE requests...

CVE-2026-108667

Oct 10, 2026 21:49:50 UTC

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to restore deleted AI prompt templates by calling the revertRecycleBin endpoint. Attackers can send PUT requests to /airag...

CVE-2026-108666

Oct 10, 2026 21:49:49 UTC

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the deleteBatch handler of AiragPromptsController that allows any authenticated user to delete AI prompt templates. Low-privileged attackers can obtain prompt ids fro...