Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 06 Sep 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls of the file jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/llm/controller/AiragModelController.java. Such manipulation of the argument credential leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 3.9.5 is able to resolve this issue. The name of the patch is a2be896f753936956ee6863b632b8e5a0231345c. You should upgrade the affected component. | |
| Title | JeecgBoot AiragModelController.java exportXls access control | |
| First Time appeared |
Jeecgboot
Jeecgboot jeecgboot |
|
| Weaknesses | CWE-266 CWE-284 |
|
| CPEs | cpe:2.3:a:jeecgboot:jeecgboot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jeecgboot
Jeecgboot jeecgboot |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-06T22:30:10.626Z
Reserved: 2026-09-06T04:13:03.167Z
Link: CVE-2026-86228
No data.
Status : Received
Published: 2026-09-06T23:17:38.990
Modified: 2026-09-06T23:17:38.990
Link: CVE-2026-86228
No data.
OpenCVE Enrichment
Updated: 2026-09-06T23:30:04Z
