๐Ÿ” CVE Alert

CVE-2026-108665

MEDIUM 4.3

JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/edit

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragPromptsController edit handler that allows any authenticated user to modify AI prompt templates. Low-privileged attackers can send PUT or POST requests to /airag/prompts/edit with a template id to overwrite prompt text and model parameters created by administrators or other users.

CWE CWE-862
Vendor jeecgboot
Product jeecgboot
Published Oct 10, 2026
Stay Ahead of the Next One

Get instant alerts for jeecgboot jeecgboot

Be the first to know when new medium vulnerabilities affecting jeecgboot jeecgboot are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

jeecgboot / JeecgBoot
0 โ‰ค 3.9.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/JeecgBoot/poc_airag_prompts_recycle.py github.com: https://github.com/jeecgboot/JeecgBoot/blob/e3b9dc0aefe1943d9772b026f64ed671a7c82802/jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/prompts/controller/AiragPromptsController.java#L103-L109 vulncheck.com: https://www.vulncheck.com/advisories/jeecgboot-through-3.9.5-missing-authorization-via-airag-prompts-edit

Credits

Yaqi Chao